{"record":{"id":"f0991d7eaadeae70","repo":"jdx/mise","slug":"lockfile-requires-ruby-provenance-but-github-attestations","errorCode":null,"errorMessage":"lockfile requires Ruby provenance but GitHub attestations are disabled or the precompiled source is not a GitHub repository","messagePattern":"lockfile requires Ruby provenance but GitHub attestations are disabled or the precompiled source is not a GitHub repository","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/plugins/core/ruby.rs","lineNumber":845,"sourceCode":"            .filter(|info| info.url.as_deref() == Some(url.as_str()));\n        let reuse_provenance = locked_info.is_some_and(|info| info.has_checksum_and_provenance())\n            && !Settings::get().force_provenance_verify();\n        if let Some((algorithm, expected)) = locked_info\n            .and_then(|info| info.checksum.as_deref())\n            .and_then(|checksum| checksum.split_once(':'))\n        {\n            hash::ensure_checksum(&tarball_path, expected, Some(ctx.pr.as_ref()), algorithm)?;\n        }\n        let locked_provenance = tv\n            .lock_platforms\n            .get_mut(&platform_key)\n            .and_then(|pi| pi.provenance.take());\n\n        // Verify GitHub artifact attestations for precompiled binaries\n        // Returns Ok(true) if verified, Ok(false) if skipped, Err if failed\n        let verified = if reuse_provenance {\n            if self.detect_precompiled_provenance().is_none() {\n                bail!(\n                    \"lockfile requires Ruby provenance but GitHub attestations are disabled or the precompiled source is not a GitHub repository\"\n                );\n            }\n            true\n        } else {\n            self.verify_github_artifact_attestations(ctx.pr.as_ref(), &tarball_path, &tv.version)\n                .await?\n        };\n\n        // Record provenance only if verification actually succeeded (not skipped)\n        if verified {\n            let pi = tv.lock_platforms.entry(platform_key.clone()).or_default();\n            pi.provenance = Some(ProvenanceType::GithubAttestations);\n        }\n\n        // Enforce lockfile provenance\n        if let Some(ref expected) = locked_provenance {\n            let got = tv","sourceCodeStart":827,"sourceCodeEnd":863,"githubUrl":"https://github.com/jdx/mise/blob/533346cc374382b41ec5ff70536252b2e96e725c/src/plugins/core/ruby.rs#L827-L863","documentation":"mise lockfiles can record provenance requirements; when reusing a locked precompiled ruby install, the plugin requires GitHub artifact attestations to be verifiable. If reuse_provenance is true but detect_precompiled_provenance() returns None — attestations disabled in settings or the precompiled source is not a GitHub repository — the install bails rather than installing unverified binaries.","triggerScenarios":"`mise install ruby` with a lockfile that recorded provenance, where either the ruby attestations setting is disabled, or ruby.precompiled_url points to a non-GitHub source so attestations cannot be checked.","commonSituations":"Restoring a lockfile on a machine with attestations disabled; switching ruby.precompiled_url to a mirror while keeping a provenance-bearing mise.lock; CI runners with network-restricted GitHub access.","solutions":["Re-enable GitHub artifact attestations (the ruby attestations setting) so provenance can be verified","Remove or regenerate the lockfile entry so it no longer requires provenance (delete mise.lock or re-lock without provenance)","Point ruby.precompiled_url back at the official GitHub releases repository"],"exampleFix":"// before\n[settings]\nruby_attestations = false // with provenance-bearing mise.lock\n// after\n[settings]\nruby_attestations = true","handlingStrategy":"validation","validationCode":"// before installing from a provenance-bearing lockfile, confirm attestations can run\nconst hasGh = await $`gh auth status`.nothrow();\nif (lockRequiresProvenance && !attestationsEnabled) {\n  throw new Error(\"lockfile provenance needs ruby attestations enabled and a GitHub-hosted precompiled source\");\n}","typeGuard":null,"tryCatchPattern":"try {\n  await $`mise install ruby`;\n} catch (e) {\n  if (String(e).includes(\"Ruby provenance\")) {\n    await $`mise settings set ruby_attestations true`;\n    await $`mise install ruby`;\n  } else throw e;\n}","preventionTips":["Keep attestations enabled wherever mise.lock files with provenance are used","If you mirror ruby precompileds off GitHub, regenerate locks without provenance requirements","Ensure CI runners can reach GitHub's attestation endpoints"],"tags":["ruby","security","attestation","lockfile"],"backgroundTag":"checksum-mismatch","analyzedSha":"533346cc374382b41ec5ff70536252b2e96e725c","analyzedAt":"2026-09-17T13:35:38.149Z","contentChangedAt":"2026-09-17T13:35:38.149Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}