jdx/mise · error
npm: is locked with an embedded-aube dependency graph, but…
Error message
npm:{} is locked with an embedded-aube dependency graph, but npm.package_manager is set to {}; use the embedded aube package manager or refresh the lockfile What it means
In npm's prepare_install_version, mise checks consistency between the lockfile's embedded-aube dependency graph and the configured npm.package_manager. If the lockfile contains an aube lock (revision-2 style dependency graph) but package_manager is npm/yarn/pnpm (not the embedded aube), mise bails because the lockfile can only be honored by the embedded aube manager.
Solutions
- Switch back to the embedded aube package manager: remove the `npm.package_manager` override or set it to "aube".
- Run `mise lock` with package_manager = "aube" to refresh the lockfile, or regenerate the lockfile under your current package manager so it no longer embeds an aube graph.
- Install unlocked (`mise install` without --locked) if you don't need lockfile enforcement, then re-lock.
Example fix
// before (mise.toml) [settings] npm.package_manager = "npm" // after [settings] npm.package_manager = "aube"
Defensive patterns
Strategy: validation
Validate before calling
# before locked install, ensure package_manager matches the lockfile's graph mise settings get npm.package_manager # must be "aube" if mise.lock embeds an aube graph
Prevention
- Standardize npm.package_manager across the team (commit it in mise.toml [settings])
- Regenerate mise.lock after changing package_manager
- Don't mix package_manager settings between global config and project config
When it happens
Trigger: mise.lock was generated with npm.package_manager = "aube" (default, embedding a dependency graph), then a user sets `npm.package_manager = "npm"` (or yarn/pnpm) in settings and runs `mise install --locked` / locked install of an npm:{} tool with aube_lock present.
Common situations: A teammate commits a lockfile generated with default settings; another contributor has `npm.package_manager = "npm"` set globally or in mise.toml and tries a locked install.
Understand the failure class
Background: Conflicting config options: "cannot be used together" — configuration validation errors across open-source libraries — this error's family across 162 libraries.
Related errors
- npm: dependency graph does not match root version ; run…
- npm: has no embedded-aube dependency graph in the revision…
- additional_artifacts must be an array in lockfile
- apk info failed
- apt-cache policy failed
AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17).
Data as JSON: /api/errors/d5644f22ecd853f5.
Report an issue: GitHub.
Appendix: source
Thrown at src/backend/npm.rs:532
let package_manager = self
.package_manager_for_install(&ctx.config, Some(&ctx.ts))
.await;
if package_manager == NpmPackageManager::Aube
&& tv.aube_lock.is_none()
&& let Some(version) = tv
.aube_install_path_version()
.or_else(|| tv.legacy_aube_install_path_version())
.map(str::to_string)
{
tv.version = version;
}
let source_lockfile_version = if tv.resolved_from_lockfile() {
crate::lockfile::version_for_request(&ctx.config, &tv.request)?
} else {
None
};
if tv.aube_lock.is_some() && package_manager != NpmPackageManager::Aube {
eyre::bail!(
"npm:{} is locked with an embedded-aube dependency graph, but npm.package_manager is set to {}; use the embedded aube package manager or refresh the lockfile",
self.tool_name(),
package_manager
);
}
if package_manager == NpmPackageManager::Aube
&& tv.resolved_from_lockfile()
&& tv.aube_lock.is_none()
&& ctx.locked
&& source_lockfile_version.is_some_and(|v| v >= 2)
{
eyre::bail!(
"npm:{} has no embedded-aube dependency graph in the revision 2 lockfile; run `mise lock` to repair it or disable locked mode",
self.tool_name()
);
}
if package_manager == NpmPackageManager::Aube
&& tv.aube_lock.is_none()View on GitHub (pinned to 533346cc37)