jdx/mise · error
lockfile requires Ruby provenance but GitHub attestations…
Error message
lockfile requires Ruby provenance but GitHub attestations are disabled or the precompiled source is not a GitHub repository
What it means
mise lockfiles can record provenance requirements; when reusing a locked precompiled ruby install, the plugin requires GitHub artifact attestations to be verifiable. If reuse_provenance is true but detect_precompiled_provenance() returns None — attestations disabled in settings or the precompiled source is not a GitHub repository — the install bails rather than installing unverified binaries.
Solutions
- Re-enable GitHub artifact attestations (the ruby attestations setting) so provenance can be verified
- Remove or regenerate the lockfile entry so it no longer requires provenance (delete mise.lock or re-lock without provenance)
- Point ruby.precompiled_url back at the official GitHub releases repository
Example fix
// before [settings] ruby_attestations = false // with provenance-bearing mise.lock // after [settings] ruby_attestations = true
Defensive patterns
Strategy: validation
Validate before calling
// before installing from a provenance-bearing lockfile, confirm attestations can run
const hasGh = await $`gh auth status`.nothrow();
if (lockRequiresProvenance && !attestationsEnabled) {
throw new Error("lockfile provenance needs ruby attestations enabled and a GitHub-hosted precompiled source");
} Try / catch
try {
await $`mise install ruby`;
} catch (e) {
if (String(e).includes("Ruby provenance")) {
await $`mise settings set ruby_attestations true`;
await $`mise install ruby`;
} else throw e;
} Prevention
- Keep attestations enabled wherever mise.lock files with provenance are used
- If you mirror ruby precompileds off GitHub, regenerate locks without provenance requirements
- Ensure CI runners can reach GitHub's attestation endpoints
When it happens
Trigger: `mise install ruby` with a lockfile that recorded provenance, where either the ruby attestations setting is disabled, or ruby.precompiled_url points to a non-GitHub source so attestations cannot be checked.
Common situations: Restoring a lockfile on a machine with attestations disabled; switching ruby.precompiled_url to a mirror while keeping a provenance-bearing mise.lock; CI runners with network-restricted GitHub access.
Understand the failure class
Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.
Related errors
- lockfile generation would change the recorded signer…
- lockfile generation would downgrade additional artifact…
- lockfile generation would downgrade recorded provenance…
- Python locks require credential-free HTTP artifact URLs…
- refusing to write dependency sidecar through symlink
AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17).
Data as JSON: /api/errors/f0991d7eaadeae70.
Report an issue: GitHub.
Appendix: source
Thrown at src/plugins/core/ruby.rs:845
.filter(|info| info.url.as_deref() == Some(url.as_str()));
let reuse_provenance = locked_info.is_some_and(|info| info.has_checksum_and_provenance())
&& !Settings::get().force_provenance_verify();
if let Some((algorithm, expected)) = locked_info
.and_then(|info| info.checksum.as_deref())
.and_then(|checksum| checksum.split_once(':'))
{
hash::ensure_checksum(&tarball_path, expected, Some(ctx.pr.as_ref()), algorithm)?;
}
let locked_provenance = tv
.lock_platforms
.get_mut(&platform_key)
.and_then(|pi| pi.provenance.take());
// Verify GitHub artifact attestations for precompiled binaries
// Returns Ok(true) if verified, Ok(false) if skipped, Err if failed
let verified = if reuse_provenance {
if self.detect_precompiled_provenance().is_none() {
bail!(
"lockfile requires Ruby provenance but GitHub attestations are disabled or the precompiled source is not a GitHub repository"
);
}
true
} else {
self.verify_github_artifact_attestations(ctx.pr.as_ref(), &tarball_path, &tv.version)
.await?
};
// Record provenance only if verification actually succeeded (not skipped)
if verified {
let pi = tv.lock_platforms.entry(platform_key.clone()).or_default();
pi.provenance = Some(ProvenanceType::GithubAttestations);
}
// Enforce lockfile provenance
if let Some(ref expected) = locked_provenance {
let got = tvView on GitHub (pinned to 533346cc37)