{"record":{"id":"d9c57ce201c49b87","repo":"jdx/mise","slug":"mise-lock-says-the-vendor-s-own-packslip-was-accepted-for","errorCode":null,"errorMessage":"mise.lock says the vendor's own packslip was accepted for {}, but this release is a repackager's; remove the entry from mise.lock to accept that","messagePattern":"mise\\.lock says the vendor's own packslip was accepted for (.+?), but this release is a repackager's; remove the entry from mise\\.lock to accept that","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/backend/packslip.rs","lineNumber":1335,"sourceCode":"        );\n        let platform_key = self.get_platform_key();\n        // The signer describes the release, so every platform's lock entry\n        // speaks for it, not only this host's.\n        for info in tv.lock_platforms.values() {\n            if let Some(locked) = &info.signer\n                && *locked != signer\n            {\n                bail!(\n                    \"mise.lock says {} signed {}, but this release is signed by {signer}; remove the entry from mise.lock to accept the new signer\",\n                    locked,\n                    tv.style()\n                );\n            }\n            if info.attested_by.is_none()\n                && info.signer.is_some()\n                && verified.attested_by == packslip::Attestor::Repackager\n            {\n                bail!(\n                    \"mise.lock says the vendor's own packslip was accepted for {}, but this release is a repackager's; remove the entry from mise.lock to accept that\",\n                    tv.style()\n                );\n            }\n        }\n\n        // A lockfile pins the exact artifact. Without one, choose the best\n        // compatible artifact for this host, including the glibc fallback.\n        let artifact =\n            match select_locked_artifact(&statement, tv.lock_platforms.get(&platform_key)) {\n                Some(artifact) => artifact,\n                None => {\n                    select_compatible_artifact(\n                        &statement.predicate.artifacts,\n                        &HostPlatform::current(),\n                        opts.variant().as_deref(),\n                        raw_opts.get(\"ignore_requirements\") == Some(\"true\"),\n                    )","sourceCodeStart":1317,"sourceCodeEnd":1353,"githubUrl":"https://github.com/jdx/mise/blob/533346cc374382b41ec5ff70536252b2e96e725c/src/backend/packslip.rs#L1317-L1353","documentation":"mise.lock records whether the previously accepted packslip was the vendor's own or a repackager's. If the lock shows a vendor-signed packslip was accepted but the new release is signed by a repackager, mise refuses: silently switching from vendor attestations to third-party repackaging weakens the trust chain, so the user must remove the lock entry to opt in.","triggerScenarios":"install_payload sees info.attested_by.is_none() && info.signer.is_some() && verified.attested_by == Attestor::Repackager while a vendor signer entry exists in mise.lock — the release changed from vendor-signed to repackager-signed.","commonSituations":"A project switches to a repackaging distributor (e.g. a distro-style re-publisher) for new releases; a fork's releases replace vendor releases on the same tool; lockfile predates the packaging change.","solutions":["Confirm the repackager is trusted, then remove the tool's entry from mise.lock and reinstall","Pin to the last vendor-signed version","Switch the tool's source to the vendor's original releases in mise.toml","Record the accepted repackager in mise.lock deliberately after reviewing its provenance"],"exampleFix":"// before: mise.lock holds vendor signer, release now repackaged\n[tools.foo.2.0.0]\nsigner = \"vendor-identity\"\n// after: remove entry and re-lock to accept the repackager\nmise lock --refresh foo && mise install foo","handlingStrategy":"validation","validationCode":"jq '.tools' mise.lock  # check signer/attested_by entries before switching release sources","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Pin tool sources explicitly so repackager releases cannot silently replace vendor ones","Review mise.lock attestation entries when switching versions","Only accept repackagers after reviewing their provenance"],"tags":["packslip","security","repackager","mise-lock"],"backgroundTag":"checksum-mismatch","analyzedSha":"533346cc374382b41ec5ff70536252b2e96e725c","analyzedAt":"2026-09-17T13:35:38.149Z","contentChangedAt":"2026-09-17T13:35:38.149Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}