jdx/mise · error

lockfile requires Ruby provenance but GitHub attestations…

Error message

lockfile requires Ruby provenance but GitHub attestations are disabled or the precompiled source is not a GitHub repository

What it means

mise lockfiles can record provenance requirements; when reusing a locked precompiled ruby install, the plugin requires GitHub artifact attestations to be verifiable. If reuse_provenance is true but detect_precompiled_provenance() returns None — attestations disabled in settings or the precompiled source is not a GitHub repository — the install bails rather than installing unverified binaries.

Solutions

  1. Re-enable GitHub artifact attestations (the ruby attestations setting) so provenance can be verified
  2. Remove or regenerate the lockfile entry so it no longer requires provenance (delete mise.lock or re-lock without provenance)
  3. Point ruby.precompiled_url back at the official GitHub releases repository

Example fix

// before
[settings]
ruby_attestations = false // with provenance-bearing mise.lock
// after
[settings]
ruby_attestations = true
Defensive patterns

Strategy: validation

Validate before calling

// before installing from a provenance-bearing lockfile, confirm attestations can run
const hasGh = await $`gh auth status`.nothrow();
if (lockRequiresProvenance && !attestationsEnabled) {
  throw new Error("lockfile provenance needs ruby attestations enabled and a GitHub-hosted precompiled source");
}

Try / catch

try {
  await $`mise install ruby`;
} catch (e) {
  if (String(e).includes("Ruby provenance")) {
    await $`mise settings set ruby_attestations true`;
    await $`mise install ruby`;
  } else throw e;
}

Prevention

When it happens

Trigger: `mise install ruby` with a lockfile that recorded provenance, where either the ruby attestations setting is disabled, or ruby.precompiled_url points to a non-GitHub source so attestations cannot be checked.

Common situations: Restoring a lockfile on a machine with attestations disabled; switching ruby.precompiled_url to a mirror while keeping a provenance-bearing mise.lock; CI runners with network-restricted GitHub access.

Understand the failure class

Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.

Related errors


AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17). Data as JSON: /api/errors/f0991d7eaadeae70. Report an issue: GitHub.

Appendix: source

Thrown at src/plugins/core/ruby.rs:845

            .filter(|info| info.url.as_deref() == Some(url.as_str()));
        let reuse_provenance = locked_info.is_some_and(|info| info.has_checksum_and_provenance())
            && !Settings::get().force_provenance_verify();
        if let Some((algorithm, expected)) = locked_info
            .and_then(|info| info.checksum.as_deref())
            .and_then(|checksum| checksum.split_once(':'))
        {
            hash::ensure_checksum(&tarball_path, expected, Some(ctx.pr.as_ref()), algorithm)?;
        }
        let locked_provenance = tv
            .lock_platforms
            .get_mut(&platform_key)
            .and_then(|pi| pi.provenance.take());

        // Verify GitHub artifact attestations for precompiled binaries
        // Returns Ok(true) if verified, Ok(false) if skipped, Err if failed
        let verified = if reuse_provenance {
            if self.detect_precompiled_provenance().is_none() {
                bail!(
                    "lockfile requires Ruby provenance but GitHub attestations are disabled or the precompiled source is not a GitHub repository"
                );
            }
            true
        } else {
            self.verify_github_artifact_attestations(ctx.pr.as_ref(), &tarball_path, &tv.version)
                .await?
        };

        // Record provenance only if verification actually succeeded (not skipped)
        if verified {
            let pi = tv.lock_platforms.entry(platform_key.clone()).or_default();
            pi.provenance = Some(ProvenanceType::GithubAttestations);
        }

        // Enforce lockfile provenance
        if let Some(ref expected) = locked_provenance {
            let got = tv

View on GitHub (pinned to 533346cc37)