jdx/mise · error
npm: has no embedded-aube dependency graph in the revision…
Error message
npm:{} has no embedded-aube dependency graph in the revision 2 lockfile; run `mise lock` to repair it or disable locked mode What it means
The inverse of error 93: when npm.package_manager is the embedded aube and the install is locked, mise requires the revision-2 lockfile to contain an embedded aube dependency graph (aube_lock) for the tool. If it's missing, mise bails because aube-based locked installs cannot proceed without the graph; it tells the user to repair the lockfile.
Solutions
- Run `mise lock` to regenerate the lockfile with the embedded aube dependency graph.
- Set npm.package_manager to a non-aube value (npm/yarn/pnpm) if you don't want aube-based locked installs.
- Disable locked mode (`mise install` without --locked) to bypass lockfile enforcement.
Example fix
// before: stale mise.lock without aube graph $ mise install --locked npm:prettier has no embedded-aube dependency graph... // after $ mise lock && mise install --locked
Defensive patterns
Strategy: validation
Validate before calling
# check lockfile revision and aube graph presence before locked aube install grep -n 'lockfile_version\|aube' mise.lock
Prevention
- Run `mise lock` after upgrading mise when lockfile format revisions change
- Keep the lockfile generator's package_manager consistent with installers'
- Commit regenerated lockfiles promptly
When it happens
Trigger: Locked install (`ctx.locked`) with package_manager = aube, tv.resolved_from_lockfile(), a lockfile whose source_lockfile_version >= 2, but tv.aube_lock is None — e.g. a lockfile generated by an older mise or with a different package manager, missing the aube graph section.
Common situations: Upgrading mise after the lockfile format moved to revision 2 with embedded aube graphs, while keeping an old mise.lock; a lockfile committed by a contributor using npm.package_manager = "npm" then installed by a contributor using aube.
Understand the failure class
Background: "not installed", "pip install", "required for": how missing-dependency errors surface across open-source libraries — this error's family across 34 libraries.
Related errors
- npm: dependency graph does not match root version ; run…
- npm: is locked with an embedded-aube dependency graph, but…
- additional_artifacts must be an array in lockfile
- aube lockfile mapping keys must be strings
- aube lockfile must contain a mapping
AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17).
Data as JSON: /api/errors/88b706e85dcc6a94.
Report an issue: GitHub.
Appendix: source
Thrown at src/backend/npm.rs:544
let source_lockfile_version = if tv.resolved_from_lockfile() {
crate::lockfile::version_for_request(&ctx.config, &tv.request)?
} else {
None
};
if tv.aube_lock.is_some() && package_manager != NpmPackageManager::Aube {
eyre::bail!(
"npm:{} is locked with an embedded-aube dependency graph, but npm.package_manager is set to {}; use the embedded aube package manager or refresh the lockfile",
self.tool_name(),
package_manager
);
}
if package_manager == NpmPackageManager::Aube
&& tv.resolved_from_lockfile()
&& tv.aube_lock.is_none()
&& ctx.locked
&& source_lockfile_version.is_some_and(|v| v >= 2)
{
eyre::bail!(
"npm:{} has no embedded-aube dependency graph in the revision 2 lockfile; run `mise lock` to repair it or disable locked mode",
self.tool_name()
);
}
if package_manager == NpmPackageManager::Aube
&& tv.aube_lock.is_none()
&& (source_lockfile_version.is_some_and(|v| v >= 2)
|| Self::aube_lock_creation_enabled(&tv))
{
tv.aube_lock = Some(self.resolve_aube_lock(&tv).await?);
}
if let Some(lock) = &tv.aube_lock {
let lock = if !ctx.locked && lock.load().is_err() {
lock.refresh()?
} else {
lock.clone()
};
self.validate_aube_lock(&tv, lock.load()?)?;View on GitHub (pinned to 533346cc37)