jdx Release Notes

Follow

267 release notes curated from 3 sources by the Releasebot Team. Last updated: Jul 22, 2026

Get this feed:

jdx Products

  • Jul 21, 2026
    • Date parsed from source:
      Jul 21, 2026
    • First seen by Releasebot:
      Jul 22, 2026
    jdx logo

    hk by jdx

    v1.52.0: Monorepo subprojects and working-tree linting

    hk adds monorepo support with nested subproject configs and per-directory mise environments, plus a new --unstaged mode for linting only working-tree changes. It also brings a Markdown formatter and several correctness fixes for branch guards, empty remotes, commit scopes, and version messages.

    This release brings hk to monorepos with nested subprojects configs and per-directory mise environments, adds a --unstaged flag for linting only working-tree changes, and ships a batch of correctness fixes for branch guards, empty remotes, and conventional commit scopes.

    Added

    subprojects for monorepos (@jdx) #1094

    The root hk.pkl can list literal directories or globs, and each subproject's own hk.pkl is merged into the root run scoped to its directory. Step working directories and glob matching are relative to the subdirectory, flat step names are prefixed with <dir>: (e.g. packages/web:eslint) for --step/skip_steps, and a subproject's env applies only to its own steps. Paired with this, HK_MISE=1 now resolves mise env --json per step dir, so subproject-local tools land on PATH — including for structured argv commands.

    // hk.pkl (repo root)
    subprojects = List("frontend", "packages/*")
    
    // frontend/hk.pkl
    hooks {
      ["check"] {
        steps { ["eslint"] = (Builtins.eslint) { batch = true } }
      }
    }
    

    --unstaged flag (@jdx) #1093

    Available on hk check, hk fix, and hk run <hook>, this selects only unstaged and untracked files (excluding staged files) without stashing — the strict inverse of --staged. It's aimed at agent-stop hooks that need to lint just the files an AI agent touched in the working tree. Conflicts with --staged, --all, --files, --from-ref/--to-ref, --glob, --pr, and --stash.

    rumdl_format builtin (@risu729) #1080

    Adds a dedicated Markdown formatter using rumdl fmt --check --diff / rumdl fmt, separate from the existing rumdl linter, mirroring the linter/formatter split hk already uses for ruff, taplo, and tombi.

    ["rumdl_format"] = Builtins.rumdl_format
    

    Fixed

    Branch guard allows detached HEAD (@jdx) #1075

    The no_commit_to_branch guard treated git symbolic-ref exiting nonzero as fatal, blocking commits created during operations like interactive rebase where HEAD is detached. It now treats a detached HEAD as "not on a protected branch" while still surfacing genuine Git errors. Fixes discussion #1074.

    Pre-push works against an empty remote (@sshine) #1090

    When a pre-push hook runs before the first push, the unresolvable base ref no longer fails the run; hk falls back to listing all files at the target ref. This is @sshine's first contribution.

    hk util skips config loading (@jdx) #1078

    Builtins like trailing-whitespace shell out to hk util, and each child was loading project and user Pkl config it never used. Utility commands now run with default settings, avoiding redundant parallel evaluation that was a likely source of intermittent failures under normal concurrency. Fixes discussion #1077.

    mise formatter no longer batches (@risu729) #1079

    The builtin had batch = true even though mise fmt processes project config itself and takes no file arguments, so multiple matched files could launch duplicate whole-project jobs. It now runs once per invocation.

    Conventional commit scope validation (@LordAizen1) #1071

    check-conventional-commit now rejects empty scopes (feat(): ...) and malformed scopes with junk after the closing paren (feat(scope)(x): ...), which the previous check accepted. Valid forms like feat(scope)!: ... still pass. This is @LordAizen1's first contribution.

    min_hk_version error message (@smasato) #1070

    The running and required versions were swapped in the "version is less than the minimum required" error; the message now reports them correctly.

    New Contributors

    @sshine made their first contribution in #1090

    @LordAizen1 made their first contribution in #1071

    Full Changelog: v1.51.0...v1.52.0

    💚 Sponsor hk

    hk is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise, aube, and more. Work on hk is funded by sponsorships.

    If hk has sped up your pre-commit loop or made linting feel less painful, please consider sponsoring at jdx.dev. Sponsorships are what keep hk moving and the project independent.

    Original source
  • Jul 20, 2026
    • Date parsed from source:
      Jul 20, 2026
    • First seen by Releasebot:
      Jul 21, 2026
    jdx logo

    mise by jdx

    vfox-v2026.7.16

    mise releases vfox 2026.7.16

    Release vfox 2026.7.16

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from jdx and hundreds of other software products.

    Create account
  • Jul 20, 2026
    • Date parsed from source:
      Jul 20, 2026
    • First seen by Releasebot:
      Jul 21, 2026
    jdx logo

    mise by jdx

    v2026.7.11: Task Source Tracking and Activation Speedups

    mise ships a broad release that sharpens task and config handling, expands bootstrap and registry support, and speeds up startup and installs. It also fixes remote file tasks, shell activation, platform edge cases, and several validation and performance issues.

    This release sharpens task handling around remote files, global config, and tool selectors, trims redundant work from shell activation, and fixes several bootstrap and platform-specific edge cases.

    Note

    This is the first published release since v2026.7.7 — versions 2026.7.8 through 2026.7.10 were tagged but never published due to a release pipeline issue. Their changes are included here; see Also in this release below.

    Added

    config: structured tool definitions now accept version, path, prefix, and ref selectors consistently in root [tools], inline task definitions, task templates, and file-task headers. Exactly one selector is required, and conflicting, missing, or non-string selectors now fail with a clear configuration error instead of silently defaulting or panicking. (#11069 by @risu729)

    node = { version = "20" }
    go = { prefix = "1.22" }
    python = { ref = "main" }
    shellcheck = { path = "/opt/shellcheck" }
    

    Fixed

    task: remote HTTP and Git-backed task files now have their #MISE headers parsed, so metadata like tools, description, and hide and inline TOML overrides are honored just like local file tasks. Git-backed task files are also made executable after cloning and on cache hits. (#11111 by @Marukome0743)

    task: file tasks loaded from user-global or system configs are now correctly treated as global regardless of their include path, so custom global scripts appear under mise tasks --global, stay out of --local, and use the invoking project root. (#11106 by @risu729)

    task: mise tasks info, extended listings, task help, and the MCP tasks resource now report every configuration source contributing to a task, with a new config_sources array in JSON output. Changing metadata in a TOML overlay now correctly invalidates the merged file task's cache. (#11098 by @risu729)

    watch: mise --env <profile> watch now propagates the selected environment to the watched task, so profile-specific tasks resolve correctly on each rerun. (#11114 by @Marukome0743)

    http: raw executables (such as PHP PHARs like Composer) installed via the HTTP backend are now created readable as well as executable (mode 0755 rather than 0711), fixing "Could not open input file" errors for interpreters run by non-owner users. (#11135 by @jdx)

    java: mise latest java@<vendor> now prefers the base vendor variant over dashed specializations and sorts multi-feature vendor prefixes correctly. (#11109 by @roele)

    config: reject conflicting tool selectors at parse time (see Added). (#11069 by @risu729)

    bootstrap: systemd timers can now reference a managed service by its bare TOML key (e.g. unit = "dotfiles-maintain"), which resolves to dev.mise.<name>.service. Fully qualified names like nginx.service are still written verbatim. (#11128 by @jdx)

    bootstrap: Homebrew casks that declare auto_updates are now accepted instead of failing with an unsupported-lifecycle error. (#11107 by @casparbreloh)

    bootstrap: macOS defaults handling now treats a missing key or domain as unset rather than erroring during initial setup. (#11118 by @roele)

    windows: mise uninstall now removes dangling runtime version pointer files (like 16 or latest) and cleans up the now-empty tool directory. (#11095 by @JamBalaya56562)

    Performance

    activate: the redundant initial prompt hook that ran immediately after activation is now skipped for bash, zsh, and fish when the session is unchanged, avoiding an extra mise process on shell startup. (#11130, #11131, #11134 by @jdx)

    backend: archive extraction and macOS hdiutil/pkgutil waits now run via block_in_place, so parallel installs no longer starve download progress and other tasks of runtime threads. (#11136 by @jdx)

    Registry

    Allow the reviewed @nubjs/nub postinstall lifecycle script to run via the npm backend so upgrades keep the ~/.nub/shims hardlinks refreshed; default-deny behavior is preserved for all other packages. (#11126 by @risu729)

    Documentation

    environments: clarify mise directory variables (#11127 by @jdx)

    Fix dead VersionFox and MCP documentation links (#11117 by @Bartok9)

    Add an example showing how to alias multiple tools from one GitHub release (#11110 by @LukasKnuth)

    Also in this release: v2026.7.8–v2026.7.10

    Due to a release pipeline issue, versions 2026.7.8 through 2026.7.10 were tagged but never published. This is the first release since v2026.7.7, so it also ships everything below.

    Added

    bootstrap: package manager plugins — vfox Lua plugins can now act as system package managers, with a declarative [bootstrap.plugins] config and mise bootstrap plugins apply|status commands. Declared plugins install before built-in packages, then plugin-managed packages apply once host tools are available. (#11023, #11024 by @jdx)

    bootstrap: new mise bootstrap repos update and mise bootstrap repos exec commands. Unpinned [bootstrap.repos] entries are intentionally never pulled by declarative apply; repos update gives an explicit fetch + fast-forward path (with dry-run and path filtering), and repos exec runs a command across configured checkouts. mise bootstrap --update now also updates repos. (#11022 by @jdx)

    registry: opt-in floating registries — with registry_floating, mise fetches the latest released registry metadata (and the current aqua registry) instead of the release-pinned copies. Useful on distributions whose mise package lags behind releases while registry entries keep changing. (#10971 by @jdx)

    backend: exact-version fast path — when a request is an exact semver version, the cargo, npm, go, gem, pipx, and dotnet backends now skip fetching the remote version list entirely and let the underlying installer validate it. This speeds up exact pins without a lockfile, first-time mise install [email protected], and mise x [email protected]. (#11013 by @Turbo87, #11070 by @jdx)

    task: dependencies whose templated names render to an empty string are now skipped, so templates can conditionally disable a dependency. Empty templated dependency args are omitted as well. (#11057 by @risu729, #11055 by @jdx)

    Fixed

    http: mise now fails fast when the network is unavailable: DNS resolver failures are treated as non-retryable, a process-local circuit opens after hard DNS/connection failures, and remote-version lookups are capped at 3 seconds under prefer_offline. Shims, shell activation, and mise x make one bounded attempt instead of grinding through full retry schedules per endpoint. (#11066 by @jdx)

    config: stricter, clearer configuration validation: env directive value aliases (#11062), env.mise directives (#11053), and the experimental monorepo root key (#11052) are deprecated, and non-string postinstall hooks are rejected at parse time (#11061) (all by @risu729)

    hooks: hook definitions are validated more strictly — unknown table fields (#11047) and nested hook arrays (#11051) are rejected, and the spawned-scripts form is deprecated (#11043) (all by @risu729)

    schema: a large batch of JSON schema corrections so editors validate real configs correctly: OCI copy entries (#11009), bootstrap shell activation (#11004) and bootstrap hooks (#11039), structured task tool options (#11021), required watch file patterns (#11040), plugin manifest fields (#11035), root hook definitions (#11041), integer types for integer settings (#11037), array-typed deps provider paths (#11064) (all by @risu729), and systemd timer/lifecycle options (#11050 by @jdx)

    dry runs no longer cause side effects: task setup is skipped (#11015), install hooks are previewed instead of executed (#11010), and mise prune --dry-run preserves runtime symlinks (#11017) (all by @risu729)

    bootstrap: Homebrew cask metadata is preserved (#11012) and macOS metadata files in cask artifacts are ignored (#11063); repo origins are compared transport-agnostically so git@ vs https:// remotes don't trigger spurious mismatches (#11034 by @jeremy); static systemd units no longer break bootstrap status (#11056 by @jdx)

    backend: prerelease versions without a separator (like 1.2.3rc1) are detected correctly (#11032 by @jdx); cargo sparse-index version discovery is restored (#11011 by @Turbo87); go resolves direct package module prefixes (#11054 by @jdx)

    install: false install env values are treated as removals (#11033 by @risu729)

    lockfile: platform-specific tool option variants are preserved instead of being collapsed (#10999 by @jdx)

    shell: hyphenated tool names work in shell integrations (#10961 by @risu729), and bash deactivate no longer errors on empty array expansions under set -u (#11026 by @jdx)

    shim: recursion is prevented when the directory env is filtered (#10982 by @risu729)

    task: file tasks resolve source files relative to the task directory (#11073 by @JamBalaya56562), and tasks generated from templates inherit the template's output setting (#11059 by @risu729)

    launchd: bootout EIO for not-loaded agents is tolerated on macOS (#10965 by @hsbt)

    nix: TZDIR is set so timezone tests pass in the sandbox build (#11019 by @coryzibell)

    Performance

    startup: ~2ms shaved off every invocation — config lookup no longer compiles ~200 glob patterns per startup (literal filenames are stat'd directly), and the clap command tree is built once instead of twice. mise version drops from 8.1ms to 6.6ms, hook-env from 10.9ms to 9.3ms. (#11025 by @jdx)

    release: release binaries for linux-x64 and macos-arm64 are now built with profile-guided optimization, trained on a hermetic offline workload covering config load, toolset resolution, hook-env, env rendering, tasks, and exec — ~10% faster on hot paths and ~4% smaller binaries (#11031 by @jdx). macOS tarballs now target macOS 12 (#11027 by @jdx).

    runtime: default tokio worker threads are capped at 16, avoiding oversized thread pools on many-core machines (#11029 by @jdx)

    Refactor

    tar extraction, inspection, and verification are consolidated onto jdx-tar, removing the system tar fallback and a duplicate tar implementation — consistent archive behavior across platforms (#11028 by @jdx)

    Registry

    add zmx (github:neurosnap/zmx) (#11006 by @offbyone)

    docker-compose switched from the aqua to the github backend (#10823 by @konono)

    eza switched from the asdf to the vfox backend (#11068 by @jdx)

    Documentation

    templates: clarify exec behavior in dry runs (#11018 by @risu729)

    New Contributors

    @Bartok9 made their first contribution in #11117

    @LukasKnuth made their first contribution in #11110

    @jeremy made their first contribution in #11034

    @Turbo87 made their first contribution in #11011

    @coryzibell made their first contribution in #11019

    Full Changelog: v2026.7.7...v2026.7.11

    💚 Sponsor mise

    mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

    If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

    Original source
  • Jul 20, 2026
    • Date parsed from source:
      Jul 20, 2026
    • First seen by Releasebot:
      Jul 2, 2026
    • Modified by Releasebot:
      Jul 21, 2026
    jdx logo

    mise by jdx

    mise-sigstore-v2026.7.1

    mise releases mise-sigstore 2026.7.1

    Release mise-sigstore 2026.7.1

    Original source
  • Jul 17, 2026
    • Date parsed from source:
      Jul 17, 2026
    • First seen by Releasebot:
      Jul 19, 2026
    jdx logo

    fnox by jdx

    v1.31.0: Composable Profiles

    fnox adds composable multi-profile support, letting users stack multiple active profiles with ordered overrides and new profile-aware commands and builders. It also improves Proton Pass handling by pointing locked sessions to session unlock instead of a generic auth hint.

    A small release headlined by composable multi-profile support, plus a friendlier Proton Pass error when your session is locked.

    Added

    Compose multiple active profiles (#605) -- @gaojunran

    You can now activate more than one profile at a time as an ordered overlay stack. The top-level config is the base, and each profile is layered on top in order, with later profiles overriding earlier ones on key conflicts.

    # Repeatable flags
    fnox -P aws -P prod exec -- ./app
    # Comma-separated
    fnox -P aws,prod exec -- ./app
    # Environment variable
    FNOX_PROFILE=aws,prod fnox exec -- ./app
    

    The effective config resolves as top-level config + profiles.aws + profiles.prod, and fnox.<profile>.toml files are loaded for each active profile in order. Write commands (set, remove, import, sync, provider add/remove) target the last active profile by default, and the full profile stack is factored into the daemon's request protocol, socket path, and cache key. Library users get a new with_profiles() builder.

    Fixed

    Proton Pass suggests unlocking a locked session (#612) -- @TyceHerrman

    pass-cli reports locked sessions as "Session is locked. Please unlock your session and try again.", but fnox previously fell through to a generic configuration/authentication hint. Locked sessions are now recognized and fnox points you at pass-cli session unlock instead of offering the configured login command. All other Proton Pass error mappings (login, key storage, agent reason, missing fields, missing secrets, generic CLI errors) are unchanged.

    New Contributors

    @gaojunran made their first contribution in #605

    @syhol made their first contribution in #614

    Full Changelog: v1.30.0...v1.31.0

    💚 Sponsor fnox

    fnox is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise, aube, hk, and more. Keeping fnox secure, maintained, and free is funded by sponsors.

    If fnox is handling secrets or config for you or your team, please consider sponsoring at jdx.dev. Sponsorships are what let fnox stay independent and the project keep moving.

    Original source
  • Similar to jdx with recent updates:

  • Jul 17, 2026
    • Date parsed from source:
      Jul 17, 2026
    • First seen by Releasebot:
      Jul 17, 2026
    jdx logo

    mise by jdx

    vfox-v2026.7.15

    mise releases vfox 2026.7.15

    Release vfox 2026.7.15

    Original source
  • Jul 17, 2026
    • Date parsed from source:
      Jul 17, 2026
    • First seen by Releasebot:
      Jul 17, 2026
    jdx logo

    mise by jdx

    v2026.7.10

    mise skips remote discovery for exact versions in more backends.

    (backend) skip remote discovery for exact versions in more back…

    Original source
  • Jul 16, 2026
    • Date parsed from source:
      Jul 16, 2026
    • First seen by Releasebot:
      Jul 17, 2026
    jdx logo

    mise by jdx

    vfox-v2026.7.13

    mise releases vfox 2026.7.13.

    Release vfox 2026.7.13

    Original source
  • Jul 16, 2026
    • Date parsed from source:
      Jul 16, 2026
    • First seen by Releasebot:
      Jul 17, 2026
    jdx logo

    mise by jdx

    v2026.7.8

    mise adds repos update and exec commands in bootstrap.

    (bootstrap) add repos update and exec commands by @jdx in [#110…

    Original source
  • Jul 16, 2026
    • Date parsed from source:
      Jul 16, 2026
    • First seen by Releasebot:
      Jul 2, 2026
    • Modified by Releasebot:
      Jul 17, 2026
    jdx logo

    mise by jdx

    aqua-registry-v2026.7.3

    mise releases aqua-registry 2026.7.3.

    Release aqua-registry 2026.7.3

    Original source
  • Jul 15, 2026
    • Date parsed from source:
      Jul 15, 2026
    • First seen by Releasebot:
      Jul 16, 2026
    jdx logo

    mise by jdx

    vfox-v2026.7.12

    mise releases vfox 2026.7.12.

    Release vfox 2026.7.12

    Original source
  • Jul 15, 2026
    • Date parsed from source:
      Jul 15, 2026
    • First seen by Releasebot:
      Jul 16, 2026
    jdx logo

    mise by jdx

    v2026.7.7: Monorepo deps, systemd timers, and OAuth reliability

    mise releases monorepo dependency provider support, systemd bootstrap timers, and stronger GitHub token refresh and cache handling for concurrent runs. It also improves asset selection, task templating, status display, schema support, and adds the microsandbox registry entry.

    This release extends dependency providers and systemd bootstrap to monorepo and timer-based workflows, and hardens GitHub OAuth token refreshes and cache clearing against concurrent mise processes.

    Added

    deps: experimental mise deps --monorepo runs dependency providers across every explicitly configured [monorepo].config_roots entry, aligned with mise install --monorepo. Provider IDs are qualified by config root (e.g. //apps/api:uv) so repeated provider names across subprojects no longer collide, and mise installs the union of tools declared across participating roots before running providers. Plain mise deps remains scoped to the current config root. (#10975 by @jdx)

    monorepo_root = true

    [monorepo]

    config_roots = ["apps/", "packages/"]

    mise deps --monorepo

    mise deps --monorepo --only //apps/api:uv

    bootstrap: manage systemd user timers alongside services via [bootstrap.linux.systemd.units]. Timer entries render to .timer units with scheduling (on_boot_sec, on_unit_active_sec, on_unit_inactive_sec, on_calendar), persistence, and timers.target linkage. Services gain optional directives including type, remain_after_exit, exec_stop, start/stop timeouts, no_new_privileges, and private_tmp. When a unit name switches between service and timer, the stale sibling unit is stopped, disabled, and removed on apply. (#10984 by @jdx)

    Fixed

    github: serialize OAuth token refreshes across mise processes. Single-use refresh tokens were only guarded by an in-process mutex, so parallel mise runs could burn the same token or overwrite the cache with stale data. The full read-refresh-write cycle now holds a filesystem lock, re-reads the cache after acquiring it, and writes atomically. Rejected refreshes now surface a sanitized error with reauthorization guidance instead of falling back silently to anonymous requests. (#10995 by @jdx)

    cache: mise cache clear no longer fails with DirectoryNotEmpty when another mise process (e.g. hook-env) recreates cache files mid-removal. Removal now retries with bounded backoff and tolerates concurrently recreated entries, while permission and other errors still propagate. (#10993 by @jdx)

    github: skip OS package and installer assets (.apk, .deb, .rpm, DMG/PKG, MSI/MSIX/AppX and sidecars) during automatic asset selection for the github:, gitlab:, and forgejo: backends, so releases containing only unsupported packages now report that no platform asset matches instead of installing an unusable file. Explicit asset_pattern and URL selection are unchanged. (#11001 by @risu729)

    aqua: honor explicit false overrides for rosetta2, windows_arm_emulation, and no_asset, so a version or platform override can disable inherited emulation or asset flags instead of being treated as omitted. (#11002 by @risu729)

    vfox: support short annotated-tag refs in plugin source URLs (e.g. a .git URL followed by #v1.0.0), resolving explicit refs against exact remote branch and tag namespaces so annotated tags no longer fail to check out. (#10998 by @junior-ricon)

    task: render Tera templates in nested task-level tool option arrays and tables, and preserve their structure through resolution instead of dropping structured values. (#10960 by @risu729)

    bootstrap: add Homebrew-compatible Array#second, #third, #fourth, and #fifth helpers to the cask shim, fixing casks (such as OrbStack) that reference version.csv.second. (#10992 by @casparbreloh)

    status: status.show_env output now respects the status.truncate setting instead of always truncating. (#10983 by @ytjmt)

    schema: add bootstrap.macos.launchd.agents.<name>.start_calendar_interval to the published schema (single schedule or array), so strict TOML validators and editors accept valid launchd calendar configurations. (#11008 by @risu729)

    Registry

    Add microsandbox (aqua:superradcompany/microsandbox) (#10985 by @joealden).

    New Contributors

    @junior-ricon made their first contribution in #10998

    @ytjmt made their first contribution in #10983

    @casparbreloh made their first contribution in #10992

    Full Changelog: v2026.7.6...v2026.7.7

    💚 Sponsor mise

    mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

    If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

    Original source
  • Jul 14, 2026
    • Date parsed from source:
      Jul 14, 2026
    • First seen by Releasebot:
      Jul 16, 2026
    jdx logo

    hk by jdx

    v1.51.0: Structured argv and disjunctive selectors

    hk ships structured argv commands and match_any selectors for safer, more flexible file matching, plus a new sherif builtin for TypeScript and JavaScript monorepos. It also fixes quiet and silent output, hook argument duplication, stash lock waits, and Linux auto-batching limits.

    Two configuration expansions land in this release: shell-free argv commands with per-file argument expansion, and match_any selectors that combine globs and types with OR semantics. Alongside them, correctness fixes for --quiet/--silent, config-based hook argument forwarding, transient index locks, and Linux argument-size limits.

    Added

    Structured argv commands (@jdx) #1067. A step's check/fix/check_list_files/check_diff can now be a Command with an explicit argv list that runs a binary via PATH without a shell. Standalone {{files}} and {{workspace_files}} entries expand to one argument per file (raw paths), so names with spaces or shell metacharacters are passed literally. Auto-batching, hk test, progress output, and fix suggestions all go through shared Command rendering, and many builtins (prettier, ruff, biome, ...) have moved to structured commands. Existing string and platform Script commands are unchanged; structured commands can't be combined with shell or prefix.

    check = new Command {
    argv = List("wc", "-c", "{{files}}")
    }
    

    match_any disjunctive file selectors (@risu729) #1055. Clauses compose with OR semantics; glob and types within a clause compose with AND. match_any cannot be mixed with the top-level glob or types, and empty selectors are rejected at validation time. {{globs}} and progress text reflect the combined patterns. The shellcheck and shfmt builtins have adopted it so they also pick up extensionless shell scripts detected by shebang, without giving up their extension globs.

    ["shellcheck"] {
    match_any = List(
    new { glob = List("**/*.sh", "**/*.bash") },
    new { types = List("sh", "bash") }
    )
    check = "shellcheck {{files}}"
    }
    

    sherif builtin (@smasato) #1062. Adds sherif, the opinionated zero-config linter for TypeScript/JavaScript monorepos. check = "sherif" / fix = "sherif --fix --no-install"; sherif always scans from the repo root, so the commands take no file arguments. Globs cover **/package.json and **/pnpm-workspace.yaml; auto-suggested when "sherif" appears in package.json.

    ["sherif"] = Builtins.sherif
    

    Fixed

    --quiet and --silent really suppress output now (@smasato) #1058. Previously these flags only lowered the log level and switched progress to text mode, which streams every update on a new line rather than hiding anything. They now set ProgressOutput::Quiet so progress lines and successful-step summaries are gone; --quiet still prints failed-step summaries (essential diagnostic), --silent prints nothing but exit code. --stats is suppressed under both. Informational println!s in init/install/migrate were routed through info! so the flags apply there too. CI/non-interactive text-mode behavior is unchanged.

    Config-based hooks no longer duplicate arguments (@jdx) #1065. Git 2.54+ already appends hook arguments to hook.<name>.command, and hk was also expanding "$@", so argument-bearing hooks received every argument twice. For pre-push this meant the duplicated remote/URL were parsed as an explicit file list, which overrode push-range discovery and silently skipped file-filtered steps. hook_run_args no longer appends "$@"; legacy .git/hooks/ shims still use it via git_hook_content. Fixes discussion #1063.

    Stash waits out transient index locks (@jdx) #1060. Shell-based stash paths now resolve the worktree lock via git rev-parse --git-path index.lock and sleep with bounded backoff (up to ~775ms) before running git stash push, so a briefly held lock from another Git process no longer aborts the hook. A persistent lock still surfaces as a normal Git error after the wait window; libgit2 stash_save is unchanged. Fixes discussion #1056.

    Linux per-argument size limit respected in auto-batching (@jdx) #1066. hk passes each rendered command to the shell as one sh -c argument, and Linux limits each argument to 32 pages (~128 KiB) independently of the aggregate ARG_MAX. Batching now caps rendered commands using both the existing ARG_MAX / 2 margin and MAX_ARG_STRLEN, sizes each chunk independently so later, longer paths cannot overflow a batch, and returns a clear error when even a single-file command cannot fit. Fixes discussion #1061.

    Documentation

    Vertically center social link icons on the docs site (@smasato) #1059.

    Full Changelog: v1.50.0...v1.51.0

    💚 Sponsor hk

    hk is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools including mise, aube, and more. Work on hk is funded by sponsorships.

    If hk has sped up your pre-commit loop or made linting feel less painful, please consider sponsoring at jdx.dev. Sponsorships are what keep hk moving and the project independent.

    Original source
  • Jul 14, 2026
    • Date parsed from source:
      Jul 14, 2026
    • First seen by Releasebot:
      Jul 15, 2026
    jdx logo

    mise by jdx

    v2026.7.6: Sandbox defaults, Flatpak bootstrap, and smarter task output

    mise adds task output style controls, stronger sandbox defaults, broader bootstrap and registry support, and a raft of fixes across config, backend, GitHub, npm, cargo, and more. It also updates quiet task output behavior and other breaking task variable changes.

    Added

    task: per-task output style field, decoupled from verbosity, so styles like prefix and quietness combine freely #10885

    sandbox: global [settings.sandbox] deny defaults (deny_all, deny_read, deny_write, deny_net, deny_env) #10940

    bootstrap: Flatpak package support for [bootstrap.packages] on Linux #10951

    oci: reproducible host path copy layers via mise oci build --copy HOST_PATH:IMAGE_PATH and [[oci.copy]] #10952

    doctor: mise doctor now warns when a mise shim is shadowed by an earlier executable in PATH #10919

    aqua: support for private github_content and github_archive packages via authenticated GitHub API endpoints #10915

    task: task-level timeout values now render Tera templates #10959

    http: http_download_timeout setting caps total download wall-clock time (default 30 minutes) #10920

    registry: add git-town (aqua:git-town/git-town) #10935 and bundler (gem:bundler) #10939

    Fixed

    backend: reinstall rolling versions (e.g. nightly) when the installed content is outdated #10827

    backend: align migrated backend resolution #10969

    config: keep already-installed versions eligible when minimum_release_age is configured #10973

    config: let user table-syntax tool options override registry defaults #10924

    config: reload settings when config is reset so bootstrap phases use a consistent snapshot #10945

    config: warn when a tool version uses an unsupported npm-style semver range #10916

    config: add Tera contrib helpers #10970

    task: preserve structured task-level tool options (arrays/tables such as os, depends, install_env) #10958

    task: isolate usage_* variables per invocation so nested tasks don't inherit stale parser output #10963

    task: invalidate auto freshness after a failed rerun #10953

    task: respect configured includes directory when editing/adding file tasks #10955

    s3: resolve cross-platform lockfile URLs for locked mode #10873

    bootstrap: preserve symlinks when extracting DMGs and always detach on copy failure #10949

    bootstrap: support localized brew casks (language, on_system_conditional) and reuse existing Ruby #10950

    erlang: lock source install outcomes #10937

    github: align SLSA provenance with the selected asset #10928

    github: treat bin/rename_exe as install-time options #10925

    npm: isolate version queries from project cwd #10927

    cargo: own the cargo-binstall compile fallback #10926

    registry: normalize backend platform selectors #10938

    registry: rename the podman binary to podman-remote #10826

    file: ignore malformed pax metadata during sparse detection #10978

    copr: fix x86_64 builds (nasm/cmake for Fedora, PREBUILT_NASM for RHEL/EPEL) #10947 and add PIE flag for aws-lc probe #10974

    toolset: preserve ref selector install identity #10942

    Changed

    cargo: disable cargo-quickinstall by default; opt back in with cargo.binstall_quickinstall = true #10923

    registry: revert preferring aqua for codex #10922

    Performance

    aqua: skip public reachability probes for packages marked private #10914

    Documentation

    aqua: document local custom registries #10966

    config: clarify sub-version arithmetic #10943

    Breaking Changes

    task: --quiet / quiet = true / MISE_QUIET=1 no longer collapse task output to un-prefixed interleave; they now preserve the resolved style. Use --output quiet (or -o interleave) for the old behavior #10885

    task: usage_* variables are now invocation-local; workflows that injected them as implicit inputs must declare an input with env= instead #10963

    💚 Sponsor mise

    mise is maintained by @jdx, an open source developer for entire.io, the title sponsor of the jdx.dev open source tools. Development is funded by sponsors.

    If mise saves you or your team time, please consider sponsoring at jdx.dev. Individual and company sponsorships keep mise fast, free, and independent.

    Original source
  • Jul 14, 2026
    • Date parsed from source:
      Jul 14, 2026
    • First seen by Releasebot:
      Jul 10, 2026
    • Modified by Releasebot:
      Jul 15, 2026
    jdx logo

    mise by jdx

    vfox-v2026.7.11

    mise lists Release vfox 2026.7.11.

    Release vfox 2026.7.11

    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.