jdx/mise · error

npm: is locked with an embedded-aube dependency graph, but…

Error message

npm:{} is locked with an embedded-aube dependency graph, but npm.package_manager is set to {}; use the embedded aube package manager or refresh the lockfile

What it means

In npm's prepare_install_version, mise checks consistency between the lockfile's embedded-aube dependency graph and the configured npm.package_manager. If the lockfile contains an aube lock (revision-2 style dependency graph) but package_manager is npm/yarn/pnpm (not the embedded aube), mise bails because the lockfile can only be honored by the embedded aube manager.

Solutions

  1. Switch back to the embedded aube package manager: remove the `npm.package_manager` override or set it to "aube".
  2. Run `mise lock` with package_manager = "aube" to refresh the lockfile, or regenerate the lockfile under your current package manager so it no longer embeds an aube graph.
  3. Install unlocked (`mise install` without --locked) if you don't need lockfile enforcement, then re-lock.

Example fix

// before (mise.toml)
[settings]
npm.package_manager = "npm"

// after
[settings]
npm.package_manager = "aube"
Defensive patterns

Strategy: validation

Validate before calling

# before locked install, ensure package_manager matches the lockfile's graph
mise settings get npm.package_manager  # must be "aube" if mise.lock embeds an aube graph

Prevention

When it happens

Trigger: mise.lock was generated with npm.package_manager = "aube" (default, embedding a dependency graph), then a user sets `npm.package_manager = "npm"` (or yarn/pnpm) in settings and runs `mise install --locked` / locked install of an npm:{} tool with aube_lock present.

Common situations: A teammate commits a lockfile generated with default settings; another contributor has `npm.package_manager = "npm"` set globally or in mise.toml and tries a locked install.

Understand the failure class

Background: Conflicting config options: "cannot be used together" — configuration validation errors across open-source libraries — this error's family across 162 libraries.

Related errors


AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17). Data as JSON: /api/errors/d5644f22ecd853f5. Report an issue: GitHub.

Appendix: source

Thrown at src/backend/npm.rs:532

        let package_manager = self
            .package_manager_for_install(&ctx.config, Some(&ctx.ts))
            .await;
        if package_manager == NpmPackageManager::Aube
            && tv.aube_lock.is_none()
            && let Some(version) = tv
                .aube_install_path_version()
                .or_else(|| tv.legacy_aube_install_path_version())
                .map(str::to_string)
        {
            tv.version = version;
        }
        let source_lockfile_version = if tv.resolved_from_lockfile() {
            crate::lockfile::version_for_request(&ctx.config, &tv.request)?
        } else {
            None
        };
        if tv.aube_lock.is_some() && package_manager != NpmPackageManager::Aube {
            eyre::bail!(
                "npm:{} is locked with an embedded-aube dependency graph, but npm.package_manager is set to {}; use the embedded aube package manager or refresh the lockfile",
                self.tool_name(),
                package_manager
            );
        }
        if package_manager == NpmPackageManager::Aube
            && tv.resolved_from_lockfile()
            && tv.aube_lock.is_none()
            && ctx.locked
            && source_lockfile_version.is_some_and(|v| v >= 2)
        {
            eyre::bail!(
                "npm:{} has no embedded-aube dependency graph in the revision 2 lockfile; run `mise lock` to repair it or disable locked mode",
                self.tool_name()
            );
        }
        if package_manager == NpmPackageManager::Aube
            && tv.aube_lock.is_none()

View on GitHub (pinned to 533346cc37)