{"record":{"id":"31c4efa36f6b699c","repo":"jdx/mise","slug":"unexpected-provenance-for-tv","errorCode":null,"errorMessage":"unexpected provenance for {tv}","messagePattern":"unexpected provenance for (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/lockfile/generate.rs","lineNumber":872,"sourceCode":"                .ensure_provenance_setting_enabled(tv, platform),\n            BackendType::Core\n                if matches!(ba.full_without_opts().as_str(), \"core:python\" | \"core:ruby\") =>\n            {\n                crate::backend::ensure_provenance_setting_enabled(tv, platform, |provenance| {\n                    let settings = Settings::get();\n                    let enabled = if ba.full_without_opts() == \"core:python\" {\n                        settings\n                            .python\n                            .github_attestations\n                            .unwrap_or(settings.github_attestations)\n                    } else {\n                        settings\n                            .ruby\n                            .github_attestations\n                            .unwrap_or(settings.github_attestations)\n                    };\n                    if !provenance.is_github_attestations() {\n                        bail!(\"unexpected provenance for {tv}\");\n                    }\n                    Ok(!enabled)\n                })\n            }\n            _ => Ok(()),\n        }\n    };\n    validate(&tv)?;\n    for artifact in &info.additional_artifacts {\n        tv.lock_platforms.get_mut(platform).unwrap().provenance = artifact.provenance.clone();\n        validate(&tv)?;\n    }\n    Ok(())\n}\n\nstruct ProgressGuard<'a> {\n    report: &'a dyn crate::ui::progress_report::SingleReport,\n    finished: bool,","sourceCodeStart":854,"sourceCodeEnd":890,"githubUrl":"https://github.com/jdx/mise/blob/533346cc374382b41ec5ff70536252b2e96e725c/src/lockfile/generate.rs#L854-L890","documentation":"`validate_provenance_settings` cross-checks that the provenance actually recorded for a tool version matches what the current settings require. For tools like Ruby (which layer `settings.ruby.github_attestations` over the global `github_attestations`), if a provenance record exists but is not of the expected GitHub-attestations kind, it bails with `unexpected provenance for {tv}`.","triggerScenarios":"Calling `is_current` or `generate` on a lockfile entry for a tool version whose stored provenance type doesn't match the backend's expected kind — e.g. a lockfile written by a different backend or older mise version recording non-GitHub provenance where GitHub attestations are expected/required.","commonSituations":"Upgrading mise across a provenance format change; hand-editing or migrating lockfiles; switching a tool between backends (e.g. from a generic backend to ruby core) so the recorded provenance no longer matches; stale lockfiles from a colleague using different settings.","solutions":["Regenerate the lockfile with the current mise version and current settings so provenance is rewritten in the expected form","Delete the stale lockfile (or affected tool entries) and re-lock","Ensure `github_attestations` settings match how the lockfile was originally produced","Avoid mixing lockfiles produced under different backend/settings configurations"],"exampleFix":"# before: stale lockfile with unexpected provenance\n# after: regenerate\nrm mise.lock && mise lock","handlingStrategy":"validation","validationCode":"// before trusting the lockfile, check provenance kind matches settings\nif lockfile_entry.provenance\n    .as_ref()\n    .map(|p| !p.is_github_attestations())\n    .unwrap_or(false)\n{\n    // regenerate: stored provenance doesn't match github_attestations settings\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Regenerate lockfiles after upgrading mise or changing attestation settings","Share identical settings.toml across the team so lockfiles are produced uniformly","Don't hand-edit or migrate lockfiles between different backend configurations","Delete stale lockfiles when provenance mismatch errors appear"],"tags":["lockfile","provenance","validation"],"backgroundTag":"schema-validation-failed","analyzedSha":"533346cc374382b41ec5ff70536252b2e96e725c","analyzedAt":"2026-09-17T13:35:38.149Z","contentChangedAt":"2026-09-17T13:35:38.149Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}