jdx/mise · error
mise.lock says the vendor's own packslip was accepted for
Error message
mise.lock says the vendor's own packslip was accepted for {}, but this release is a repackager's; remove the entry from mise.lock to accept that What it means
mise.lock records whether the previously accepted packslip was the vendor's own or a repackager's. If the lock shows a vendor-signed packslip was accepted but the new release is signed by a repackager, mise refuses: silently switching from vendor attestations to third-party repackaging weakens the trust chain, so the user must remove the lock entry to opt in.
Solutions
- Confirm the repackager is trusted, then remove the tool's entry from mise.lock and reinstall
- Pin to the last vendor-signed version
- Switch the tool's source to the vendor's original releases in mise.toml
- Record the accepted repackager in mise.lock deliberately after reviewing its provenance
Example fix
// before: mise.lock holds vendor signer, release now repackaged [tools.foo.2.0.0] signer = "vendor-identity" // after: remove entry and re-lock to accept the repackager mise lock --refresh foo && mise install foo
Defensive patterns
Strategy: validation
Validate before calling
jq '.tools' mise.lock # check signer/attested_by entries before switching release sources
Prevention
- Pin tool sources explicitly so repackager releases cannot silently replace vendor ones
- Review mise.lock attestation entries when switching versions
- Only accept repackagers after reviewing their provenance
When it happens
Trigger: install_payload sees info.attested_by.is_none() && info.signer.is_some() && verified.attested_by == Attestor::Repackager while a vendor signer entry exists in mise.lock — the release changed from vendor-signed to repackager-signed.
Common situations: A project switches to a repackaging distributor (e.g. a distro-style re-publisher) for new releases; a fork's releases replace vendor releases on the same tool; lockfile predates the packaging change.
Understand the failure class
Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.
Related errors
- mise.lock says signed , but this release is signed by …
- : sha256 is , the packslip says
- packslip: : this release . If the vendor announced the…
- the packslip is for , not
- the packslip names an artifact
AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17).
Data as JSON: /api/errors/d9c57ce201c49b87.
Report an issue: GitHub.
Appendix: source
Thrown at src/backend/packslip.rs:1335
);
let platform_key = self.get_platform_key();
// The signer describes the release, so every platform's lock entry
// speaks for it, not only this host's.
for info in tv.lock_platforms.values() {
if let Some(locked) = &info.signer
&& *locked != signer
{
bail!(
"mise.lock says {} signed {}, but this release is signed by {signer}; remove the entry from mise.lock to accept the new signer",
locked,
tv.style()
);
}
if info.attested_by.is_none()
&& info.signer.is_some()
&& verified.attested_by == packslip::Attestor::Repackager
{
bail!(
"mise.lock says the vendor's own packslip was accepted for {}, but this release is a repackager's; remove the entry from mise.lock to accept that",
tv.style()
);
}
}
// A lockfile pins the exact artifact. Without one, choose the best
// compatible artifact for this host, including the glibc fallback.
let artifact =
match select_locked_artifact(&statement, tv.lock_platforms.get(&platform_key)) {
Some(artifact) => artifact,
None => {
select_compatible_artifact(
&statement.predicate.artifacts,
&HostPlatform::current(),
opts.variant().as_deref(),
raw_opts.get("ignore_requirements") == Some("true"),
)View on GitHub (pinned to 533346cc37)