jdx/mise · error

packslip: @ : verified manifest project/version differs…

Error message

packslip:{project}@{}: verified manifest project/version differs from discovery

What it means

After cryptographic verification of the packslip manifest, mise re-reads the project and version embedded inside the verified manifest and compares them with the project/version discovery requested. A mismatch means the signed content is for a different release than the one being resolved.

Solutions

  1. Fix the project/version fields in the packslip manifest so they match the release being published
  2. Correct the registry entry or requested version to match the manifest's declared project/version
  3. Ask the vendor to re-publish the manifest for the intended version

Example fix

// before (manifest)
project = 'ripgrep'
version = '14.1.0'
// after — match requested 14.1.1
project = 'ripgrep'
version = '14.1.1'
Defensive patterns

Strategy: validation

Validate before calling

// packslip authors: assert manifest metadata matches the release being cut
assert_eq!(manifest.project, project_name);
assert_eq!(manifest.version, tag_version_to_publish);

Type guard

null

Try / catch

null

Prevention

When it happens

Trigger: verified_release calls verify_bundle and then checks verified.project != project || verified.version != tv.version; happens when the manifest inside the bundle declares a different project name or version than the registry entry / requested tool version.

Common situations: Registry entry renamed but manifest not updated; manifest published for version 14.1.0 pointed at from a 14.1.1 entry; copy-paste error in the vendor's manifest metadata.

Understand the failure class

Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.

Related errors


AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17). Data as JSON: /api/errors/0f84548273cdae84. Report an issue: GitHub.

Appendix: source

Thrown at src/backend/packslip.rs:930

                (vendor.url, vendor.digest)
            }
        };
        let text = crate::packslip::fetch_text(&url).await?;
        let actual = hex::encode(Sha256::digest(text.as_bytes()));
        for expected in vendor_digest
            .iter()
            .chain(stamp.and_then(|stamp| stamp.digest.as_ref()))
        {
            if &actual != expected {
                bail!(
                    "packslip:{project}@{}: manifest digest differs from signed list",
                    tv.version
                );
            }
        }
        let verified = verify_bundle(&text, pin, !opts.allow_unlogged(), &[])?;
        if verified.project != project || verified.version != tv.version {
            bail!(
                "packslip:{project}@{}: verified manifest project/version differs from discovery",
                tv.version
            );
        }
        let scheme = verified.scheme.to_string();
        let attested_by = verified.attested_by.to_string();
        packslip_pins::check(
            project,
            Observed {
                scheme: &scheme,
                key_id: &verified.key_id,
                issuer: verified.issuer.as_deref(),
                attested_by: &attested_by,
                provenance: verified.provenance_linked,
                logged: verified.logged_at.is_some(),
            },
        )?;
        let payload = packslip::sigstore::peek_statement(&text).map_err(|e| eyre!("{e}"))?;

View on GitHub (pinned to 533346cc37)