Skip to content

Error and warning codes ​

aube emits a stable string identifier with every error and most warnings. Codes look like ERR_AUBE_NO_LOCKFILE or WARN_AUBE_IGNORED_BUILD_SCRIPTS, and they're attached as a structured field — no regex on stderr required.

Use the search box and category chips below to filter the list directly from the registry.

How to read codes ​

Default text output: errors include the code in their miette-rendered output, e.g. × foo (ERR_AUBE_NO_LOCKFILE). Warnings include the code as a structured field after the message.

ndjson output (aube --reporter ndjson <cmd>): diagnostic events include a code field. Progress and other informational events may not have one. Read the structured code when present instead of matching the human message. The reporter writes to stderr; for example:

sh
aube --reporter ndjson install 2> aube-events.ndjson
jsonc
{
  "level": "WARN",
  "code": "WARN_AUBE_IGNORED_BUILD_SCRIPTS",
  "count": 2,
  "packages": ["esbuild", "opencode-ai"],
  "message": "ignored build scripts for 2 package(s): esbuild, opencode-ai. ..."
}

Exit codes: errors exit with 1 (generic) by default. The errors called out as having a bespoke exit in the table below get a stable numeric exit code instead, so shell scripts can branch without parsing stderr.

Naming ​

  • ERR_AUBE_* — fatal errors. Process exits non-zero.
  • WARN_AUBE_* — non-fatal warnings. Install continues; the warning is informational.

aube does not emit ERR_PNPM_* codes. Where a code maps onto a pnpm concept (lockfile, peer-deps, tarball, etc.) the suffix matches pnpm's naming so the meaning is obvious to anyone familiar with pnpm's error page, but aube reserves its own prefix so the codes can evolve independently.

Stability ​

Once published, a code's identifier and meaning don't change. New codes can be added at any time. Removing or repurposing a code is a breaking change.

Bespoke exit codes follow the same contract. The exit-code allocation is grouped by category — see crates/aube-codes/src/exit.rs for the full layout — but consumers should branch on the exit value, not the category, since categories are documentation, not API.

Errors ​

Lockfile

Code Exit Description
ERR_AUBE_NO_LOCKFILE10An operation that required a lockfile (--frozen-lockfile, aube fetch, etc.) found none in the project.
ERR_AUBE_LOCKFILE_PARSE11Lockfile is structurally invalid — version guard failed, YAML shape is wrong, or the contents couldn't be parsed.
ERR_AUBE_LOCKFILE_UNSUPPORTED_FORMAT12Lockfile filename was recognized but its format isn't supported on this aube version.
ERR_AUBE_RESOLUTION_SHAPE_MISMATCH13A registry-style lockfile dependency path is backed by a git, local directory, or direct tarball resolution.
ERR_AUBE_LOCKFILE_CONFIG_MISMATCH14A frozen install found configuration, such as patch-file content, that no longer matches the lockfile.
ERR_AUBE_UNSUPPORTED_NAMED_REGISTRY15A pnpm lockfile contains registry-qualified package identities that aube cannot safely resolve yet.
ERR_AUBE_UNSUPPORTED_PNPM_LOCKFILE_VERSION16A pnpm lockfile aube cannot read: a lockfileVersion older than 9 (the pnpm 8.x and earlier formats), a malformed version, or a v9 header over a pre-v9 body.

Resolver

Code Exit Description
ERR_AUBE_NO_MATCHING_VERSION20No published version of the named package satisfies the requested range.
ERR_AUBE_NO_MATURE_MATCHING_VERSION21A version satisfying the range exists but every candidate was younger than minimumReleaseAge and minimumReleaseAgeStrict=true.
ERR_AUBE_BLOCKED_EXOTIC_SUBDEP22Transitive dep used a git: / file: / tarball specifier and blockExoticSubdeps=true.
ERR_AUBE_TRUST_DOWNGRADE23Picked version dropped trust evidence the prior version had (trustPolicy=no-downgrade).
ERR_AUBE_TRUST_MISSING_TIME24Registry's packument has no time entry for the picked version (trustPolicy=no-downgrade).
ERR_AUBE_UNKNOWN_CATALOG25A catalog:<name> reference was used but the catalog isn't defined.
ERR_AUBE_UNKNOWN_CATALOG_ENTRY26The catalog exists but has no entry for the requested package.
ERR_AUBE_PEER_CONTEXT_NOT_CONVERGED27Peer-dependency resolution didn't converge after 16 passes — usually mutually-recursive peers.
ERR_AUBE_REGISTRY_ERROR1Generic registry error from inside the resolver.
ERR_AUBE_TRUST_EXCLUDE_INVALID_VERSION_UNION1A trustPolicyExclude pattern had an invalid semver range.
ERR_AUBE_TRUST_EXCLUDE_NAME_GLOB_WITH_VERSIONS1A trustPolicyExclude pattern combined a name glob with versions.
ERR_AUBE_EXOTIC_SUBDEP_EXCLUDE_HAS_VERSION1A blockExoticSubdepsExclude entry carried a version selector, which cannot match an exotic dependency.
ERR_AUBE_EXOTIC_SUBDEP_EXCLUDE_INVALID_NAME1A blockExoticSubdepsExclude entry was not a package name, so it could never match.

Tarball / store

Code Exit Description
ERR_AUBE_TARBALL_INTEGRITY30Downloaded tarball's hash didn't match the lockfile's / packument's dist.integrity.
ERR_AUBE_TARBALL_EXTRACT31Tarball couldn't be extracted (corrupt gzip, unexpected entry shape, etc.).
ERR_AUBE_PKG_CONTENT_MISMATCH32Tarball's package.json declared a different (name, version) than the resolver expected (strictStorePkgContentCheck=true).
ERR_AUBE_GIT_ERROR33Git operation failed during a git: dep prepare or checkout.
ERR_AUBE_TARBALL_URL_MISMATCH34A registry lockfile entry's explicit tarball URL didn't match the registry metadata for that (name, version).
ERR_AUBE_NO_HOME1HOME (or platform equivalent) is unset, so aube can't locate its store.
ERR_AUBE_STORE_INDEX_SCAN_FAILED1A store maintenance command couldn't completely read or parse the cached package indexes.
ERR_AUBE_GVS_PRUNE_FAILED1The global virtual store project registry or prune walk failed.
ERR_AUBE_STORE_PRUNE_LOCK_FAILED1aube couldn't acquire the store-wide maintenance lock for pruning.
ERR_AUBE_STORE_PRUNE_FAILED1A planned content-store file couldn't be removed during pruning.

Registry / network

Code Exit Description
ERR_AUBE_PACKAGE_NOT_FOUND40Registry returned 404 for the package name.
ERR_AUBE_ACCESS_ENTITY_NOT_FOUND1Registry returned 404 for an access user, organization, or team.
ERR_AUBE_VERSION_NOT_FOUND41Package exists but the requested version doesn't.
ERR_AUBE_UNAUTHORIZED42Registry returned 401/403 — missing or invalid auth. Run aube login.
ERR_AUBE_WEB_LOGIN_RESPONSE_TOO_LARGE1The web-login token response exceeded the 64 KiB safety limit.
ERR_AUBE_OFFLINE43Offline mode and the requested resource isn't in the local cache.
ERR_AUBE_INVALID_PACKAGE_NAME44A name doesn't match npm's grammar — rejected before any I/O so a hostile manifest can't turn a package name into an arbitrary filesystem path.
ERR_AUBE_REGISTRY_WRITE_REJECTED45Registry rejected a publish/deprecate/owner write with a non-2xx response.
ERR_AUBE_MALICIOUS_PACKAGE46aube add or an install's OSV advisory check (advisoryCheck, advisoryCheckOnInstall, advisoryBloomCheck) refused a package because OSV reports it as malicious (MAL-* advisory). Hard block — confirmed-malicious advisories aren't a judgement call.
ERR_AUBE_LOW_DOWNLOAD_PACKAGE47aube add refused a package whose weekly downloads fall below lowDownloadThreshold in a non-interactive context (or when stdin is not a TTY). Pass --allow-low-downloads to bypass.
ERR_AUBE_ADVISORY_CHECK_FAILED49An OSV advisory check couldn't complete — the live API was unreachable, or the local mirror / bloom filter couldn't refresh — and the governing setting (advisoryCheck, advisoryCheckOnInstall, or advisoryBloomCheck) is required. Distinct from ERR_AUBE_MALICIOUS_PACKAGE so CI tooling can tell a network outage from a confirmed malicious advisory.

Supply chain (add-time)

Code Exit Description
ERR_AUBE_SIMILAR_PACKAGE_NAME1aube add refused a package whose name closely resembles a more popular npm package. This protects against typosquatting and slopsquatting.
ERR_AUBE_NEW_PACKAGE_NAME1aube add refused a package name first published within minimumPackageAge. This protects against newly registered slopsquatting names.
ERR_AUBE_PACKAGE_AGE_CHECK_FAILED1aube add couldn't verify a package name's registry creation time while minimumPackageAge was enabled, so the package-age gate failed closed.
ERR_AUBE_SECURITY_SCANNER_FATAL48User-configured securityScanner returned a fatal-level advisory against a package the user is trying to add. Bun-style pluggable scanner contract; the scanner itself decides what counts as fatal.
ERR_AUBE_SECURITY_SCANNER_FAILED1User-configured securityScanner couldn't be spawned, exited non-zero, timed out, or emitted unparseable JSON. Fail-closed by design: a configured scanner that can't run is treated as a refusal, not a free pass. Set securityScanner = "" to disable the integration when bootstrapping or recovering from a broken scanner.

Scripts / build

Code Exit Description
ERR_AUBE_SCRIPT_NON_ZERO_EXIT50A lifecycle script (preinstall / install / postinstall / a package.json script) exited non-zero.
ERR_AUBE_SCRIPT_SPAWN51Couldn't spawn a script's interpreter (shell missing, jail setup failed, etc.).
ERR_AUBE_BUILD_POLICY_UNSUPPORTED_VALUE1An entry in allowBuilds had a value that wasn't true/false.
ERR_AUBE_BUILD_POLICY_INVALID_VERSION_UNION1An allowBuilds pattern's version union was unparseable.
ERR_AUBE_BUILD_POLICY_WILDCARD_WITH_VERSION1An allowBuilds pattern combined a wildcard name with a version union.

Linker

Code Exit Description
ERR_AUBE_PATCH_FAILED60Applying a pnpm.patchedDependencies patch failed.
ERR_AUBE_LINK_FAILED61Symlink / junction / hardlink couldn't be created — usually permissions or filesystem support.
ERR_AUBE_MISSING_PACKAGE_INDEX62A package could not be linked because its store index was unavailable and the package was not already materialized. Re-run the install; if it persists, report it at https://github.com/aubepkg/aube/discussions.
ERR_AUBE_MISSING_STORE_FILE63A package index references a CAS shard that doesn't exist on disk. Re-run install to re-fetch.
ERR_AUBE_UNSAFE_MODULES_DIR64The configured modules directory resolves to the project root or outside it, where linker cleanup could remove unrelated files.

Manifest / workspace

Code Exit Description
ERR_AUBE_MANIFEST_PARSE70A package.json had a syntax error. The diagnostic points at the offending byte.
ERR_AUBE_WORKSPACE_PARSE71An aube-workspace.yaml / pnpm-workspace.yaml was structurally invalid.
ERR_AUBE_MANIFEST_YAML_PARSE1A workspace YAML helper file was structurally invalid (no source pointer available).
ERR_AUBE_INVALID_PACKAGE_EXTENSION1A packageExtensions entry had an invalid object shape or non-string dependency range.
ERR_AUBE_FILTER_EMPTY1--filter was passed an empty selector.
ERR_AUBE_FILTER_GIT_IO1A --filter ...[ref] selector failed to spawn git.
ERR_AUBE_FILTER_GIT_FAILED1The git subprocess for a --filter ...[ref] selector exited non-zero.

Engine / CLI

Code Exit Description
ERR_AUBE_UNSUPPORTED_ENGINE80One or more packages declared an engines constraint incompatible with the running Node/aube and engine-strict=true.
ERR_AUBE_UNKNOWN_COMMAND81The named subcommand isn't a built-in aube command and isn't a script in the manifest.
ERR_AUBE_NPM_ONLY_COMMAND82The user invoked an npm-only command (whoami, token, owner, search, pkg, set-script, stage) — aube doesn't implement these; run them with npm, or set npmPath to let aube delegate them.
ERR_AUBE_RECURSIVE_NOT_SUPPORTED1A command was invoked under --recursive but doesn't support recursive execution.
ERR_AUBE_COMPLETION_FAILED1aube completion couldn't invoke usage to render the shell completions.
ERR_AUBE_USAGE_SPEC_WRITE_FAILED1aube usage couldn't write the CLI spec to stdout; the output would have been truncated.
ERR_AUBE_REMOVE_PRIOR_INSTALL_DIR1Couldn't clean up a prior global install dir before re-installing.
ERR_AUBE_CONFIG_NESTED_AUBE_KEY1aube config set <prefix>.<sub> … was used for a key whose prefix is an aube map setting (e.g. allowBuilds.<pkg>). Such nested writes would otherwise land in .npmrc where aube doesn't read them and npm warns/errors about the unknown key — set the map in workspace yaml or package.json#aube.<prefix> instead.
ERR_AUBE_CONFLICTING_BUILD_FLAGS1aube add was passed the same package name in both --allow-build and --deny-build.
ERR_AUBE_ACCESS_INVALID_ARGUMENT1aube access received an invalid access setting, permission level, team, or package argument.
ERR_AUBE_PUBLISH_SOURCE_NOT_FOUND1aube publish was given a package directory or tarball path that doesn't exist.
ERR_AUBE_SHIM_CREATE_FAILED1aube activate <shell> couldn't create or refresh an executable shim in aube's shim directory.
ERR_AUBE_SHIM_EXEC_FAILED1A runtime tool shim resolved its target but couldn't exec or spawn the selected tool.
ERR_AUBE_RUNTIME_VERSION_UNSATISFIED83The project requires a Node.js version that isn't available and policy forbids fetching it (devEngines.runtime with onFail: "error", runtimeOnFail=error, or offline mode with nothing installed).
ERR_AUBE_RUNTIME_NO_MATCHING_VERSION84No Node.js release in the dist index satisfies the requested version (bad range, unknown LTS codename, or no build for this platform).
ERR_AUBE_RUNTIME_DOWNLOAD_FAILED85Fetching the Node.js dist index, checksum file, or release archive failed after retries.
ERR_AUBE_RUNTIME_CHECKSUM_MISMATCH86A downloaded Node.js archive's SHA-256 didn't match the lockfile pin or SHASUMS256.txt. The archive is discarded and never retried automatically.
ERR_AUBE_RUNTIME_EXTRACT_FAILED87A Node.js release archive was corrupt or contained unsafe entry paths.
ERR_AUBE_RUNTIME_MISE_INSTALL_FAILED88Delegating a Node.js install to mise failed — mise install node@<version> exited non-zero or the install wasn't discoverable afterwards. Fatal only under runtimeInstaller=mise; auto falls back to aube's own download.
ERR_AUBE_RUNTIME_UNSUPPORTED_PLATFORM89No official Node.js build exists for this OS/architecture/libc. Set nodeDownloadMirrors to a mirror that carries one, or install Node via mise/system.
ERR_AUBE_RUNTIME_IO1A filesystem operation in the runtime store failed (lock acquisition, staging, or publishing an install). Not a download failure — the message names the failing path.
ERR_AUBE_SELF_UPDATE_UNSUPPORTED_PLATFORM1aube self-update has no published aube release archive for this OS/architecture (e.g. FreeBSD, Intel macOS). Install aube via your system package manager or mise. Distinct from ERR_AUBE_RUNTIME_UNSUPPORTED_PLATFORM, which is about the Node.js download.

Misc / safety

Code Exit Description
ERR_AUBE_INSTALL_CANCELLED1An in-process install was cooperatively cancelled by its embedding host. Cancellation is observed at safe install boundaries so an in-flight filesystem phase is not abandoned mid-mutation.
ERR_AUBE_UNSAFE_INDEX_KEY90A package index key tried to escape its directory (path traversal defense in depth).
ERR_AUBE_UNSAFE_SHEBANG_INTERPRETER91A #! shebang named an unsafe interpreter when generating a shim — substituted with node instead. Reported as an error, but install continues.
ERR_AUBE_EMBED_INVALID_PROJECT1An in-process embedder was given a project directory that could not be created, inspected, or resolved.
ERR_AUBE_EMBED_INSTALL_FAILED1An in-process embedder could not initialize its host callback or received an install failure without a more specific stable code.
ERR_AUBE_EMBED_INVALID_SETTING1An in-process embedder passed a setting default whose name is not a canonical aube setting.
ERR_AUBE_EMBED_ALREADY_INITIALIZED1An in-process embedder tried to register setting defaults after the process already initialized its embedder profile.
ERR_AUBE_FFI_INVALID_ARGUMENT1A C ABI call received a null pointer, invalid UTF-8, malformed JSON, or an unsupported option value.
ERR_AUBE_FFI_UNKNOWN_HANDLE1A C ABI wait or cancellation call referenced an unknown or already-consumed operation handle.
ERR_AUBE_FFI_RUNTIME1The C ABI could not initialize or use its internal asynchronous runtime.
ERR_AUBE_FFI_PANIC1A panic was caught at the C ABI boundary before it could cross into the host process.
ERR_AUBE_UNSAFE_PACKAGE_NAME92A package/dependency alias would escape its node_modules slot if linked.
ERR_AUBE_PATCHES_TRACKING_WRITE1Couldn't write .aube-applied-patches.json after applying patches. Non-fatal; next install may miss stale patched entries.

Warnings ​

Codes prefixed WARN_AUBE_* indicate non-fatal conditions. The install proceeds; the warning surfaces something the user may want to act on. Bespoke exit codes do not apply to warnings.

pnpmfile / hooks

CodeDescription
WARN_AUBE_PNPMFILE_NOT_FOUNDA pnpmfile path (CLI arg, workspace setting, global) pointed at a missing file.
WARN_AUBE_PNPMFILE_STDERR_FORWARDERThe background task forwarding pnpmfile stderr panicked.
WARN_AUBE_PNPMFILE_CHECKSUM_FAILEDReading the local pnpmfile for checksum computation failed; the lockfile's pnpmfileChecksum field is omitted so a later install will re-resolve instead of trusting a stale value.
WARN_AUBE_HOOK_IMPORTER_MUTATEDA pnpmfile afterAllResolved hook mutated importers[...]; aube ignored the edit.
WARN_AUBE_HOOK_IMPORTER_ADDEDA pnpmfile afterAllResolved hook added a new importers[...] entry; aube ignored it.
WARN_AUBE_HOOK_IDENTITY_REWRITTENA pnpmfile hook rewrote a package's (name, version) identity; aube reverted the edit.
WARN_AUBE_HOOK_PACKAGE_ADDEDA pnpmfile hook added a wholly-new package entry; aube ignored it.

Install lifecycle

CodeDescription
WARN_AUBE_IGNORED_BUILD_SCRIPTSDep had preinstall/install/postinstall scripts but isn't on the allowBuilds allowlist. Run aube approve-builds.
WARN_AUBE_DEPRECATED_PACKAGEAn installed package version is deprecated.
WARN_AUBE_DEPRECATED_PACKAGE_SUMMARYOne or more installed package versions have deprecation warnings.
WARN_AUBE_SUSPICIOUS_LIFECYCLE_SCRIPTA dependency's lifecycle script matched a dangerous-shape heuristic (curl|sh, eval+atob, credential-file read, secret-env exfil, exfil endpoint, bare-IP HTTP). Advisory only; the allowBuilds allowlist still gates execution. Inspect the script before approving the build.
WARN_AUBE_WINDOWS_JOB_OBJECT_UNAVAILABLEWindows: couldn't create or assign a kill-on-job-close job object for a lifecycle script. The script still runs, but on abort/failure its grandchildren (node-gyp / MSBuild / node) may be orphaned. Usually caused by a restrictive parent job or enterprise policy.
WARN_AUBE_MISSING_INTEGRITYLockfile entry / registry response had no dist.integrity; importing without verification. Set strict-store-integrity=true to refuse.
WARN_AUBE_CACHE_WRITE_FAILEDCouldn't write a package index to the on-disk cache. Non-fatal.
WARN_AUBE_CLONE_STRATEGY_FALLBACKpackage-import-method=clone will silently fall back to copy if the filesystem doesn't support reflinks.
WARN_AUBE_LTHASH_MISMATCHaube's incremental install digest disagreed with a full recomputation. This indicates a bug in aube — please report it at https://github.com/aubepkg/aube/discussions.
WARN_AUBE_DELTA_INVALIDATE_FAILEDDelta install couldn't invalidate a package directory during cleanup.
WARN_AUBE_GVS_INCOMPATIBLEA package isn't compatible with aube's global virtual store; installed per-project instead.
WARN_AUBE_GVS_MODE_CHANGEDThe global virtual store was switched on or off since the last install, so aube is removing node_modules and reinstalling from scratch.
WARN_AUBE_GVS_CROSS_VOLUMEThe global virtual store (globalVirtualStoreDir, by default under cacheDir) and storeDir are on different volumes, so linking falls back to per-file copy.

Store maintenance

CodeDescription
WARN_AUBE_STORE_PRUNE_ENTRY_DISAPPEAREDA global virtual-store entry disappeared while a prune plan was being built; the preview skipped it.

Settings / config validation

CodeDescription
WARN_AUBE_INVALID_CONCURRENCYnetwork-concurrency or link-concurrency was 0 (must be ≥ 1).
WARN_AUBE_INVALID_TRUST_POLICYA trustPolicyExclude entry was malformed and skipped.
WARN_AUBE_INVALID_BUNDLED_PACKAGE_EXTENSIONA bundled package-extension entry was malformed and skipped.
WARN_AUBE_INVALID_MINIMUM_RELEASE_AGE_EXCLUDEA minimumReleaseAgeExclude entry was malformed and skipped.
WARN_AUBE_INVALID_BLOCK_EXOTIC_SUBDEPS_EXCLUDEA blockExoticSubdepsExclude entry was malformed and skipped.
WARN_AUBE_OVERRIDE_MISSING_DEPAn overrides $ref pointed at a package not in any of the importer's dependency lists.
WARN_AUBE_OVERRIDE_DOLLAR_REF_DEPRECATEDAn overrides entry used pnpm's deprecated $ version reference syntax.
WARN_AUBE_OVERRIDE_TOO_DEEPA nested overrides entry went deeper than one level (or chained > inside a group) and was skipped.
WARN_AUBE_INVALID_PEER_PATTERNA peerDependencyRules pattern was unparseable and skipped.
WARN_AUBE_INVALID_SAVE_PREFIXsave-prefix was something other than ^, ~, or empty. Falling back to ^.
WARN_AUBE_CONCURRENCY_ENV_INVALIDThe AUBE_CONCURRENCY env var was outside the [floor, ceiling] range or non-numeric.
WARN_AUBE_MANAGED_CONFIG_ENFORCEDManaged hardening config enforced a stricter value than local config, env, or CLI requested.

Update / prerelease

CodeDescription
WARN_AUBE_PRERELEASE_CHECK_SKIPPEDaube update couldn't fetch the packument or got a non-semver latest tag; preserved-prerelease check skipped for that package.
WARN_AUBE_MINIMUM_RELEASE_AGE_BLOCKED_UPDATEOne or more newer package versions were hidden because they have not satisfied minimumReleaseAge yet.
WARN_AUBE_WORKSPACE_PACKAGE_MISSING_NAMEA discovered workspace package had no name field, so update skipped local workspace version registration for it.

Audit / npmrc

CodeDescription
WARN_AUBE_AUDIT_FETCH_FAILEDaube audit --ignore-unfixable couldn't fetch a packument; advisories for that package are kept verbatim.
WARN_AUBE_TOKEN_CHMOD_FAILEDchmod 0600 on the auth token file failed; the file may be world-readable.

Registry config (trust gates)

CodeDescription
WARN_AUBE_UNTRUSTED_PROXYA *-proxy setting came from a source aube doesn't trust (committed .npmrc can't set proxies).
WARN_AUBE_UNTRUSTED_STRICT_SSL_DISABLEstrict-ssl=false came from a source aube doesn't trust. TLS validation stays on.
WARN_AUBE_INVALID_LOCAL_ADDRESSlocal-address setting wasn't a valid IP.
WARN_AUBE_INVALID_MAXSOCKETSmaxsockets was 0 or non-numeric.
WARN_AUBE_UNSCOPED_AUTH_RESCOPEDAn unscoped registry credential was pinned to the registry declared by the same config source.
WARN_AUBE_UNTRUSTED_AUTH_ENVAn auth setting from project-controlled .npmrc contained an environment variable reference and was ignored.
WARN_AUBE_UNTRUSTED_TOKEN_HELPERtokenHelper came from an untrusted source (CVE-2025-69262 class).
WARN_AUBE_INVALID_TOKEN_HELPERtokenHelper value wasn't a sanitized absolute path.
WARN_AUBE_TOKEN_HELPER_SPAWN_FAILEDtokenHelper couldn't be spawned.
WARN_AUBE_TOKEN_HELPER_NON_ZERO_EXITtokenHelper exited non-zero.

Registry HTTP retries

CodeDescription
WARN_AUBE_HTTP_RETRY_TRANSIENTRetrying after a transient HTTP status (429, 5xx).
WARN_AUBE_HTTP_RETRY_TRANSPORTRetrying after a transport / connection error.
WARN_AUBE_HTTP_RETRY_BODY_READRetrying after a response-body read error (timeout, partial body).
WARN_AUBE_HTTP_RETRY_BODY_DECODERetrying after a JSON decode error on the response body.

Registry caching / perf

CodeDescription
WARN_AUBE_PACKUMENT_CACHE_WRITECouldn't write a packument to the on-disk cache after a successful fetch. Non-fatal; next install will refetch.
WARN_AUBE_SLOW_METADATAOne or more packument fetches exceeded fetchWarnTimeoutMs. Emitted as a grouped summary so a burst of slow fetches produces one warning, not one per fetch.
WARN_AUBE_SLOW_TARBALLA tarball download fell below fetchMinSpeedKiBps.

Registry TLS / proxy

CodeDescription
WARN_AUBE_INVALID_HTTPS_PROXYhttps-proxy URL didn't parse.
WARN_AUBE_INVALID_HTTP_PROXYhttp-proxy URL didn't parse.
WARN_AUBE_INVALID_CAPer-registry CA PEM didn't parse.
WARN_AUBE_INVALID_CAFILEcafile couldn't be parsed as a PEM bundle.
WARN_AUBE_UNREADABLE_CAFILEcafile couldn't be read from disk.
WARN_AUBE_INVALID_CLIENT_CERTPer-registry client cert/key PEM pair didn't parse.

Resolver

CodeDescription
WARN_AUBE_UNSUPPORTED_PLATFORM_INSTALLA required (non-optional) dep declared a platform aube doesn't satisfy; installing anyway.
WARN_AUBE_EXOTIC_SUBDEP_SKIPPEDAn optional or peer dep used an exotic specifier and was skipped under blockExoticSubdeps=true.
WARN_AUBE_PEER_DEDUPE_COLLISIONdedupe-peers=true would have collapsed a distinct peer-variant; preserved the longer form to avoid dropping it.

Lockfile

CodeDescription
WARN_AUBE_LOCKFILE_MERGE_CONFLICTBranch-lockfile merge had conflicting entries for the same dep_path; one was chosen.
WARN_AUBE_LOCKFILE_MERGE_CLEANUP_FAILEDAfter a successful merge, removing one of the merged branch lockfiles failed.
WARN_AUBE_LOCKFILE_CONFLICT_MARKERSThe active lockfile contains Git conflict markers; aube is regenerating it from package.json.
WARN_AUBE_YARN_BERRY_UNSUPPORTEDA Yarn Berry patch: / portal: / exec: protocol — or any unrecognized protocol — was found in yarn.lock. Entry was skipped.
WARN_AUBE_LOCKFILE_MALFORMED_PEER_SUFFIXA pnpm dep_path peer suffix had unbalanced parentheses (a truncated or hand-corrupted lockfile entry). The key is preserved verbatim instead of silently dropping everything after the (, so a later install surfaces the bad entry rather than mis-resolving it.
WARN_AUBE_GLOBAL_OUTDATED_NO_LOCKFILEaube outdated -g found a global install without a lockfile and skipped that install.
WARN_AUBE_HIDDEN_LOCKFILE_BROKENThe hidden lockfile in node_modules/.aube-lock.yaml could not be parsed, so install ignored it and resolved dependencies without it.

Global installs

CodeDescription
WARN_AUBE_GLOBAL_DIR_LEGACY_LOCATIONGlobal packages were found under the pnpm-named directory aube used before it owned its own global layout ($PNPM_HOME, $XDG_DATA_HOME/pnpm, ~/Library/pnpm, %LOCALAPPDATA%\pnpm), while the current global directory holds none. Those installs are no longer visible to aube list -g / remove -g; reinstall them with aube add -g, or point AUBE_HOME at the old directory.
WARN_AUBE_GLOBAL_BIN_DIR_NOT_ON_PATHaube add -g linked a bin into a directory that is not on $PATH, so the command it installed won't be found. Add the directory to PATH, or point globalBinDir / AUBE_HOME at one that already is.

Progress UI

CodeDescription
WARN_AUBE_PROGRESS_OVERFLOWInstall progress numerator exceeded the resolved-package denominator. Display clamps to total; the warning surfaces the bookkeeping mismatch so the underlying race can be diagnosed.

Workspace recursion

CodeDescription
WARN_AUBE_WORKSPACE_TOPO_CYCLETopological sort of aube run -r / aube exec -r selected packages found a dependency cycle. Cycle members run in workspace-listing order after the rest of the topo-sorted set.

Supply chain (add-time)

CodeDescription
WARN_AUBE_SIMILAR_PACKAGE_NAMEaube add flagged a package whose name closely resembles a top-100,000 npm package. Interactive sessions prompt for confirmation; non-interactive contexts fail with ERR_AUBE_SIMILAR_PACKAGE_NAME unless explicitly allowed.
WARN_AUBE_LOW_DOWNLOAD_PACKAGEaube add flagged a package whose weekly downloads fall below lowDownloadThreshold. Interactive sessions prompt for confirmation; non-interactive contexts fail with ERR_AUBE_LOW_DOWNLOAD_PACKAGE unless --allow-low-downloads is passed.
WARN_AUBE_NEW_PACKAGE_NAMEaube add flagged a package name first published within minimumPackageAge. Interactive sessions prompt for confirmation; non-interactive contexts fail with ERR_AUBE_NEW_PACKAGE_NAME unless explicitly allowed.
WARN_AUBE_ADVISORY_CHECK_FAILEDOSV MAL-* advisory check couldn't reach the API. With advisoryCheck=on (default) install continues; with advisoryCheck=required install fails closed.
WARN_AUBE_OSV_MIRROR_REFRESH_FAILEDOSV advisory mirror used by advisoryCheckOnInstall failed to refresh (download, ETag, or zip parse error). With advisoryCheckOnInstall=on install proceeds against the previously cached index if any; with advisoryCheckOnInstall=required install fails closed with ERR_AUBE_ADVISORY_CHECK_FAILED.
WARN_AUBE_OSV_BLOOM_REFRESH_FAILEDOSV bloom-filter prefilter used by advisoryBloomCheck failed to refresh (download or format-decode error). With advisoryBloomCheck=on install proceeds against the previously cached filter if any; with advisoryBloomCheck=required install fails closed with ERR_AUBE_ADVISORY_CHECK_FAILED.
WARN_AUBE_SECURITY_SCANNER_FINDINGUser-configured securityScanner returned a warn-level advisory. Install continues — only fatal-level advisories block.

Node runtime

CodeDescription
WARN_AUBE_RUNTIME_VERSION_MISMATCHThe active Node.js doesn't satisfy the project's runtime requirement and onFail: "warn" keeps execution on the unsatisfying version.
WARN_AUBE_RUNTIME_MISE_FALLBACKruntimeInstaller=auto tried delegating a Node.js install to mise but mise failed; aube fell back to its own nodejs.org download.
WARN_AUBE_RUNTIME_PIN_NOT_RECORDEDdevEngines.runtime resolved to an exact Node.js version but the project's lockfile format (npm/yarn/bun) has no runtime entry shape, so the pin wasn't recorded. Subsequent runs re-resolve the range.

Adding a code ​

  1. Add a pub const to crates/aube-codes/src/errors.rs or warnings.rs.
  2. Add a CodeMeta entry to the local ALL slice carrying the category, one-line description, and (for errors) optional bespoke exit code. The self-tests in crates/aube-codes/src/lib.rs and exit.rs reject typos, missing descriptions, duplicate exit codes, and out-of-range exits.
  3. Reference the constant from the call site:
    • For warnings: tracing::warn!(code = aube_codes::warnings::WARN_AUBE_X, ...).
    • For thiserror enums: #[diagnostic(code(ERR_AUBE_X))].
    • For ad-hoc miette: miette::miette!(code = aube_codes::errors::ERR_AUBE_X, ...).
  4. Run mise run render to regenerate docs/error-codes.data.json.
MIT LicensejdxCopyright © 2026 jdx.dev