jdx/mise · error
npm: dependency graph does not match root version ; run…
Error message
npm:{} dependency graph does not match root version {}; run `mise lock` What it means
validate_aube_lock checks that the lockfile's embedded aube dependency graph records the root package's dependency specifier equal to the requested tool version. If the graph's root specifier for the tool differs from tv.version, the lockfile is stale relative to the requested version, and mise bails directing the user to re-lock.
Solutions
- Run `mise lock` so the dependency graph matches the requested root version.
- If the version in mise.toml is wrong, revert it to the locked version instead.
- Commit mise.toml and mise.lock changes together to keep them in sync.
Example fix
// before (mise.toml bumped without re-lock) [tools] "npm:eslint" = "9.10.0" # lockfile still has specifier = 9.9.0 // after $ mise lock # regenerates graph for 9.10.0
Defensive patterns
Strategy: validation
Validate before calling
# verify root specifier in lockfile matches mise.toml version # mise.toml: "npm:eslint" = "9.10.0" grep -A3 '\[.*dependencies.*eslint\]' mise.lock # specifier should equal 9.10.0
Prevention
- Always run `mise lock` immediately after bumping an npm tool version in mise.toml
- Commit mise.toml and mise.lock together
- Use `mise upgrade <tool>` instead of hand-editing versions so the lock stays in sync
When it happens
Trigger: Requesting npm:<tool>@X while mise.lock's aube graph maps "." -> dependencies -> <tool> -> specifier to a different version Y; mise.toml bumps the tool version without running `mise lock`; lockfile committed for a different version than the config requests.
Common situations: A developer edits the tool version in mise.toml but forgets to run `mise lock`; pulling a config change from git without the matching lockfile update; rebasing that merged version bump but not lock regeneration.
Understand the failure class
Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.
Related errors
- npm: has no embedded-aube dependency graph in the revision…
- npm: is locked with an embedded-aube dependency graph, but…
- cannot merge lockfile version
- additional_artifacts must be an array in lockfile
- aube lockfile mapping keys must be strings
AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17).
Data as JSON: /api/errors/ac9dd3050f6bed07.
Report an issue: GitHub.
Appendix: source
Thrown at src/backend/npm.rs:1546
)?;
Ok(())
}
pub(crate) fn validate_aube_lock(
&self,
tv: &ToolVersion,
lock: &crate::lockfile::AubeLock,
) -> Result<()> {
let requirement = lock
.graph
.get("importers")
.and_then(|v| v.get("."))
.and_then(|v| v.get("dependencies"))
.and_then(|v| v.get(self.tool_name()))
.and_then(|v| v.get("specifier"))
.and_then(toml::Value::as_str);
if requirement != Some(tv.version.as_str()) {
eyre::bail!(
"npm:{} dependency graph does not match root version {}; run `mise lock`",
self.tool_name(),
tv.version
);
}
Ok(())
}
pub(crate) async fn resolve_aube_lock(
&self,
tv: &ToolVersion,
) -> Result<crate::lockfile::GraphRef<crate::lockfile::AubeLock>> {
crate::backend::aube_host::init();
let temp = tempfile::tempdir()?;
let request_options = tv.request.options();
let options = NpmOptions::new(&request_options);
let allow_builds = options.allow_builds()?;
self.write_aube_embed_project(temp.path(), tv.before_date, &options, &allow_builds, false)?;View on GitHub (pinned to 533346cc37)