jdx/mise · error

npm: has no embedded-aube dependency graph in the revision…

Error message

npm:{} has no embedded-aube dependency graph in the revision 2 lockfile; run `mise lock` to repair it or disable locked mode

What it means

The inverse of error 93: when npm.package_manager is the embedded aube and the install is locked, mise requires the revision-2 lockfile to contain an embedded aube dependency graph (aube_lock) for the tool. If it's missing, mise bails because aube-based locked installs cannot proceed without the graph; it tells the user to repair the lockfile.

Solutions

  1. Run `mise lock` to regenerate the lockfile with the embedded aube dependency graph.
  2. Set npm.package_manager to a non-aube value (npm/yarn/pnpm) if you don't want aube-based locked installs.
  3. Disable locked mode (`mise install` without --locked) to bypass lockfile enforcement.

Example fix

// before: stale mise.lock without aube graph
$ mise install --locked
npm:prettier has no embedded-aube dependency graph...

// after
$ mise lock && mise install --locked
Defensive patterns

Strategy: validation

Validate before calling

# check lockfile revision and aube graph presence before locked aube install
grep -n 'lockfile_version\|aube' mise.lock

Prevention

When it happens

Trigger: Locked install (`ctx.locked`) with package_manager = aube, tv.resolved_from_lockfile(), a lockfile whose source_lockfile_version >= 2, but tv.aube_lock is None — e.g. a lockfile generated by an older mise or with a different package manager, missing the aube graph section.

Common situations: Upgrading mise after the lockfile format moved to revision 2 with embedded aube graphs, while keeping an old mise.lock; a lockfile committed by a contributor using npm.package_manager = "npm" then installed by a contributor using aube.

Understand the failure class

Background: "not installed", "pip install", "required for": how missing-dependency errors surface across open-source libraries — this error's family across 34 libraries.

Related errors


AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17). Data as JSON: /api/errors/88b706e85dcc6a94. Report an issue: GitHub.

Appendix: source

Thrown at src/backend/npm.rs:544

        let source_lockfile_version = if tv.resolved_from_lockfile() {
            crate::lockfile::version_for_request(&ctx.config, &tv.request)?
        } else {
            None
        };
        if tv.aube_lock.is_some() && package_manager != NpmPackageManager::Aube {
            eyre::bail!(
                "npm:{} is locked with an embedded-aube dependency graph, but npm.package_manager is set to {}; use the embedded aube package manager or refresh the lockfile",
                self.tool_name(),
                package_manager
            );
        }
        if package_manager == NpmPackageManager::Aube
            && tv.resolved_from_lockfile()
            && tv.aube_lock.is_none()
            && ctx.locked
            && source_lockfile_version.is_some_and(|v| v >= 2)
        {
            eyre::bail!(
                "npm:{} has no embedded-aube dependency graph in the revision 2 lockfile; run `mise lock` to repair it or disable locked mode",
                self.tool_name()
            );
        }
        if package_manager == NpmPackageManager::Aube
            && tv.aube_lock.is_none()
            && (source_lockfile_version.is_some_and(|v| v >= 2)
                || Self::aube_lock_creation_enabled(&tv))
        {
            tv.aube_lock = Some(self.resolve_aube_lock(&tv).await?);
        }
        if let Some(lock) = &tv.aube_lock {
            let lock = if !ctx.locked && lock.load().is_err() {
                lock.refresh()?
            } else {
                lock.clone()
            };
            self.validate_aube_lock(&tv, lock.load()?)?;

View on GitHub (pinned to 533346cc37)