jdx/mise · error
packslip: @ : verified manifest project/version differs…
Error message
packslip:{project}@{}: verified manifest project/version differs from discovery What it means
After cryptographic verification of the packslip manifest, mise re-reads the project and version embedded inside the verified manifest and compares them with the project/version discovery requested. A mismatch means the signed content is for a different release than the one being resolved.
Solutions
- Fix the project/version fields in the packslip manifest so they match the release being published
- Correct the registry entry or requested version to match the manifest's declared project/version
- Ask the vendor to re-publish the manifest for the intended version
Example fix
// before (manifest) project = 'ripgrep' version = '14.1.0' // after — match requested 14.1.1 project = 'ripgrep' version = '14.1.1'
Defensive patterns
Strategy: validation
Validate before calling
// packslip authors: assert manifest metadata matches the release being cut assert_eq!(manifest.project, project_name); assert_eq!(manifest.version, tag_version_to_publish);
Type guard
null
Try / catch
null
Prevention
- Generate the manifest's project/version fields from CI variables, not by hand
- Run a manifest-vs-tag linter in the release pipeline
- Review manifest metadata in the release PR diff
When it happens
Trigger: verified_release calls verify_bundle and then checks verified.project != project || verified.version != tv.version; happens when the manifest inside the bundle declares a different project name or version than the registry entry / requested tool version.
Common situations: Registry entry renamed but manifest not updated; manifest published for version 14.1.0 pointed at from a 14.1.1 entry; copy-paste error in the vendor's manifest metadata.
Understand the failure class
Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.
Related errors
- packslip: @ : manifest digest differs from signed list
- packslip: @ : manifest digest differs from signed list
- the stamp for packslip
- an exec entry with no command
- artifact target has changed
AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17).
Data as JSON: /api/errors/0f84548273cdae84.
Report an issue: GitHub.
Appendix: source
Thrown at src/backend/packslip.rs:930
(vendor.url, vendor.digest)
}
};
let text = crate::packslip::fetch_text(&url).await?;
let actual = hex::encode(Sha256::digest(text.as_bytes()));
for expected in vendor_digest
.iter()
.chain(stamp.and_then(|stamp| stamp.digest.as_ref()))
{
if &actual != expected {
bail!(
"packslip:{project}@{}: manifest digest differs from signed list",
tv.version
);
}
}
let verified = verify_bundle(&text, pin, !opts.allow_unlogged(), &[])?;
if verified.project != project || verified.version != tv.version {
bail!(
"packslip:{project}@{}: verified manifest project/version differs from discovery",
tv.version
);
}
let scheme = verified.scheme.to_string();
let attested_by = verified.attested_by.to_string();
packslip_pins::check(
project,
Observed {
scheme: &scheme,
key_id: &verified.key_id,
issuer: verified.issuer.as_deref(),
attested_by: &attested_by,
provenance: verified.provenance_linked,
logged: verified.logged_at.is_some(),
},
)?;
let payload = packslip::sigstore::peek_statement(&text).map_err(|e| eyre!("{e}"))?;View on GitHub (pinned to 533346cc37)