BoundaryML/baml · error
artifact URL must use HTTPS
Error message
artifact {name} URL must use HTTPS What it means
Each artifact entry in the release manifest must point to an https:// URL. This guard rejects non-HTTPS download locations to prevent tampering or downgrade attacks when clients fetch release binaries.
Solutions
- Change the artifact URL to an https:// endpoint
- If using an internal mirror, put it behind TLS and use its https URL
- Re-run validate() after fixing the URL
Example fix
// before url = "http://downloads.example.com/baml-linux.tar.gz" // after url = "https://downloads.example.com/baml-linux.tar.gz"
Defensive patterns
Strategy: validation
Validate before calling
fn assert_https(url: &str) -> Result<(), String> {
if url.starts_with("https://") { Ok(()) } else { Err(format!("non-HTTPS artifact URL: {url}")) }
} Prevention
- Always publish artifacts behind TLS endpoints
- Lint manifests for http:// URLs in CI
- Never hand-write URLs; copy from the release pipeline output
When it happens
Trigger: validate_artifact() is reached with an Artifact whose url field does not start with "https://" — e.g. an http:// or bare-host URL in the manifest.
Common situations: Authoring a manifest with a local mirror or http link; copying a URL from an internal artifact store that serves plain HTTP; forgetting the scheme entirely.
Understand the failure class
Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.
Related errors
- archive contains unsafe path
- Audio is not a URL
- AWS Bedrock requires s3:// URIs, but got
- Checksum mismatch: expected
- CSRF state mismatch
AI-assisted analysis of BoundaryML/baml@bd85ce9dee (2026-09-12).
Data as JSON: /api/errors/d771ffa1a563eb7d.
Report an issue: GitHub.
Appendix: source
Thrown at baml_language/crates/baml_release/src/manifest.rs:154
Ok(())
}
fn validate_artifacts(version: &str, artifacts: &BTreeMap<String, Artifact>) -> anyhow::Result<()> {
let expected: std::collections::BTreeSet<_> =
SUPPORTED_RELEASE_TARGETS.iter().copied().collect();
let actual: std::collections::BTreeSet<_> = artifacts.keys().map(String::as_str).collect();
if actual != expected {
anyhow::bail!("manifest for {version} has target set {actual:?}; expected {expected:?}");
}
for (target, artifact) in artifacts {
validate_artifact(target, artifact)?;
}
Ok(())
}
fn validate_artifact(name: &str, artifact: &Artifact) -> anyhow::Result<()> {
if !artifact.url.starts_with("https://") {
anyhow::bail!("artifact {name} URL must use HTTPS");
}
validate_sha256(&artifact.sha256)?;
Ok(())
}
fn validate_sdk(language: &str, package: &SdkPackage) -> anyhow::Result<()> {
if package.registry.is_empty() || package.package.is_empty() || package.version.is_empty() {
anyhow::bail!("sdk {language} has an empty registry, package, or version");
}
if let Some(digest) = &package.verified_package_sha256 {
validate_sha256(digest)
.map_err(|error| anyhow::anyhow!("sdk {language} package digest: {error}"))?;
}
if language == "csharp" {
if package.registry != "nuget" || package.package != "baml-bridge" {
anyhow::bail!("sdk csharp must identify nuget/baml-bridge");
}
if package.verified_package_sha256.is_none() {View on GitHub (pinned to bd85ce9dee)