Skip to content

Integrity Mismatch

An integrity mismatch means that observed content does not satisfy the recorded integrity expectation.

  1. Confirm that the correct artifact is being verified.
  2. Compare artifact identifiers and versions.
  3. Recalculate the relevant integrity value.
  4. Check whether the file changed after evidence generation.
  5. Confirm that the evidence belongs to the current artifact.

Do not replace the recorded integrity value merely to make verification succeed.

If the content was intentionally changed, generate a new evidence record for the new artifact.

If the change was unintended, restore the expected artifact before continuing.