{"record":{"id":"07fbc31cbe4e24d3","repo":"jdx/mise","slug":"mise-lock-says-signed-but-this-release-is-signed-by-signer","errorCode":null,"errorMessage":"mise.lock says {} signed {}, but this release is signed by {signer}; remove the entry from mise.lock to accept the new signer","messagePattern":"mise\\.lock says (.+?) signed (.+?), but this release is signed by (.+?); remove the entry from mise\\.lock to accept the new signer","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/backend/packslip.rs","lineNumber":1325,"sourceCode":"            key_id: &verified.key_id,\n            issuer: verified.issuer.as_deref(),\n            attested_by: &attested_by,\n            provenance: verified.provenance_linked,\n            logged: verified.logged_at.is_some(),\n        };\n        packslip_pins::check(&project, observed)?;\n        let signer = format!(\n            \"{scheme}:{}\",\n            packslip_pins::signer_of(&scheme, &verified.key_id)\n        );\n        let platform_key = self.get_platform_key();\n        // The signer describes the release, so every platform's lock entry\n        // speaks for it, not only this host's.\n        for info in tv.lock_platforms.values() {\n            if let Some(locked) = &info.signer\n                && *locked != signer\n            {\n                bail!(\n                    \"mise.lock says {} signed {}, but this release is signed by {signer}; remove the entry from mise.lock to accept the new signer\",\n                    locked,\n                    tv.style()\n                );\n            }\n            if info.attested_by.is_none()\n                && info.signer.is_some()\n                && verified.attested_by == packslip::Attestor::Repackager\n            {\n                bail!(\n                    \"mise.lock says the vendor's own packslip was accepted for {}, but this release is a repackager's; remove the entry from mise.lock to accept that\",\n                    tv.style()\n                );\n            }\n        }\n\n        // A lockfile pins the exact artifact. Without one, choose the best\n        // compatible artifact for this host, including the glibc fallback.","sourceCodeStart":1307,"sourceCodeEnd":1343,"githubUrl":"https://github.com/jdx/mise/blob/533346cc374382b41ec5ff70536252b2e96e725c/src/backend/packslip.rs#L1307-L1343","documentation":"mise.lock records which signer produced a release. During install, if any platform's lock entry names a different signer than the signer of the release currently being verified, mise fails closed: a signer change could be legitimate (key rotation) or a supply-chain attack, so the user must explicitly delete the lock entry to accept the new signer.","triggerScenarios":"install_payload iterates tv.lock_platforms and finds info.signer set and differing from the release's signer — typically after a project rotates signing keys or changes signing infrastructure.","commonSituations":"Upstream project rotated its sigstore key; tool moved from one signing CI to another; mise.lock committed long ago now conflicts with a new release; attacker-substituted release attempts to swap signers.","solutions":["Verify the new signer is legitimate (check the project's announcements/key rotation docs)","Remove the signer entry for the tool from mise.lock (`mise lock` refresh or edit the file) and re-run install","Pin to the previous version signed by the known-good signer","Audit the new release (artifact digests, provenance) before accepting"],"exampleFix":"// before: mise.lock\n[tools.foo.1.2.3]\nsigner = \"old-signer-identity\"\n// after: remove the entry so the new signer is accepted, then re-install\nmise lock --refresh foo && mise install foo","handlingStrategy":"validation","validationCode":"# Inspect the locked signer before upgrading\nmise lock ls 2>/dev/null || jq '.tools.foo' mise.lock","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Watch project announcements for signing key rotations","After upstream rotation, review the new signer then refresh mise.lock deliberately","Commit mise.lock so team members see signer changes in review"],"tags":["packslip","security","supply-chain","mise-lock"],"backgroundTag":"checksum-mismatch","analyzedSha":"533346cc374382b41ec5ff70536252b2e96e725c","analyzedAt":"2026-09-17T13:35:38.149Z","contentChangedAt":"2026-09-17T13:35:38.149Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}