BoundaryML/baml · error

artifact URL must use HTTPS

Error message

artifact {name} URL must use HTTPS

What it means

Each artifact entry in the release manifest must point to an https:// URL. This guard rejects non-HTTPS download locations to prevent tampering or downgrade attacks when clients fetch release binaries.

Solutions

  1. Change the artifact URL to an https:// endpoint
  2. If using an internal mirror, put it behind TLS and use its https URL
  3. Re-run validate() after fixing the URL

Example fix

// before
url = "http://downloads.example.com/baml-linux.tar.gz"

// after
url = "https://downloads.example.com/baml-linux.tar.gz"
Defensive patterns

Strategy: validation

Validate before calling

fn assert_https(url: &str) -> Result<(), String> {
    if url.starts_with("https://") { Ok(()) } else { Err(format!("non-HTTPS artifact URL: {url}")) }
}

Prevention

When it happens

Trigger: validate_artifact() is reached with an Artifact whose url field does not start with "https://" — e.g. an http:// or bare-host URL in the manifest.

Common situations: Authoring a manifest with a local mirror or http link; copying a URL from an internal artifact store that serves plain HTTP; forgetting the scheme entirely.

Understand the failure class

Background: "Invalid URL" errors: why new URL(), URI.parse, and reqwest::Url reject your string — missing scheme, whitespace, and bad path format — this error's family across 39 libraries.

Related errors


AI-assisted analysis of BoundaryML/baml@bd85ce9dee (2026-09-12). Data as JSON: /api/errors/d771ffa1a563eb7d. Report an issue: GitHub.

Appendix: source

Thrown at baml_language/crates/baml_release/src/manifest.rs:154

    Ok(())
}

fn validate_artifacts(version: &str, artifacts: &BTreeMap<String, Artifact>) -> anyhow::Result<()> {
    let expected: std::collections::BTreeSet<_> =
        SUPPORTED_RELEASE_TARGETS.iter().copied().collect();
    let actual: std::collections::BTreeSet<_> = artifacts.keys().map(String::as_str).collect();
    if actual != expected {
        anyhow::bail!("manifest for {version} has target set {actual:?}; expected {expected:?}");
    }
    for (target, artifact) in artifacts {
        validate_artifact(target, artifact)?;
    }
    Ok(())
}

fn validate_artifact(name: &str, artifact: &Artifact) -> anyhow::Result<()> {
    if !artifact.url.starts_with("https://") {
        anyhow::bail!("artifact {name} URL must use HTTPS");
    }
    validate_sha256(&artifact.sha256)?;
    Ok(())
}

fn validate_sdk(language: &str, package: &SdkPackage) -> anyhow::Result<()> {
    if package.registry.is_empty() || package.package.is_empty() || package.version.is_empty() {
        anyhow::bail!("sdk {language} has an empty registry, package, or version");
    }
    if let Some(digest) = &package.verified_package_sha256 {
        validate_sha256(digest)
            .map_err(|error| anyhow::anyhow!("sdk {language} package digest: {error}"))?;
    }
    if language == "csharp" {
        if package.registry != "nuget" || package.package != "baml-bridge" {
            anyhow::bail!("sdk csharp must identify nuget/baml-bridge");
        }
        if package.verified_package_sha256.is_none() {

View on GitHub (pinned to bd85ce9dee)