jdx/mise · error

mise.lock says the vendor's own packslip was accepted for

Error message

mise.lock says the vendor's own packslip was accepted for {}, but this release is a repackager's; remove the entry from mise.lock to accept that

What it means

mise.lock records whether the previously accepted packslip was the vendor's own or a repackager's. If the lock shows a vendor-signed packslip was accepted but the new release is signed by a repackager, mise refuses: silently switching from vendor attestations to third-party repackaging weakens the trust chain, so the user must remove the lock entry to opt in.

Solutions

  1. Confirm the repackager is trusted, then remove the tool's entry from mise.lock and reinstall
  2. Pin to the last vendor-signed version
  3. Switch the tool's source to the vendor's original releases in mise.toml
  4. Record the accepted repackager in mise.lock deliberately after reviewing its provenance

Example fix

// before: mise.lock holds vendor signer, release now repackaged
[tools.foo.2.0.0]
signer = "vendor-identity"
// after: remove entry and re-lock to accept the repackager
mise lock --refresh foo && mise install foo
Defensive patterns

Strategy: validation

Validate before calling

jq '.tools' mise.lock  # check signer/attested_by entries before switching release sources

Prevention

When it happens

Trigger: install_payload sees info.attested_by.is_none() && info.signer.is_some() && verified.attested_by == Attestor::Repackager while a vendor signer entry exists in mise.lock — the release changed from vendor-signed to repackager-signed.

Common situations: A project switches to a repackaging distributor (e.g. a distro-style re-publisher) for new releases; a fork's releases replace vendor releases on the same tool; lockfile predates the packaging change.

Understand the failure class

Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.

Related errors


AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17). Data as JSON: /api/errors/d9c57ce201c49b87. Report an issue: GitHub.

Appendix: source

Thrown at src/backend/packslip.rs:1335

        );
        let platform_key = self.get_platform_key();
        // The signer describes the release, so every platform's lock entry
        // speaks for it, not only this host's.
        for info in tv.lock_platforms.values() {
            if let Some(locked) = &info.signer
                && *locked != signer
            {
                bail!(
                    "mise.lock says {} signed {}, but this release is signed by {signer}; remove the entry from mise.lock to accept the new signer",
                    locked,
                    tv.style()
                );
            }
            if info.attested_by.is_none()
                && info.signer.is_some()
                && verified.attested_by == packslip::Attestor::Repackager
            {
                bail!(
                    "mise.lock says the vendor's own packslip was accepted for {}, but this release is a repackager's; remove the entry from mise.lock to accept that",
                    tv.style()
                );
            }
        }

        // A lockfile pins the exact artifact. Without one, choose the best
        // compatible artifact for this host, including the glibc fallback.
        let artifact =
            match select_locked_artifact(&statement, tv.lock_platforms.get(&platform_key)) {
                Some(artifact) => artifact,
                None => {
                    select_compatible_artifact(
                        &statement.predicate.artifacts,
                        &HostPlatform::current(),
                        opts.variant().as_deref(),
                        raw_opts.get("ignore_requirements") == Some("true"),
                    )

View on GitHub (pinned to 533346cc37)