Hmbown/CodeWhale · error · Error
Invalid checksum manifest line
Error message
Invalid checksum manifest line: ${trimmed} What it means
parseChecksumManifest parses a SHA-256 checksums file line by line; each non-empty line must match /^([a-fA-F0-9]{64})\s+\*?(.+)$/ (64 hex chars, whitespace, filename). Lines that don't match throw this error.
Solutions
- Regenerate the manifest with sha256sum: `sha256sum dist/* > SHASUMS256.txt`.
- Open the manifest and fix or remove the offending line.
- Ensure no comments/headers are present — only checksum lines are allowed.
Example fix
// before abc123 dist/codewhale.tgz // after 9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08 dist/codewhale.tgz
Defensive patterns
Strategy: validation
Validate before calling
const ok = require('fs').readFileSync('SHASUMS256.txt','utf8').split('\n').filter(Boolean).every(l => /^[a-fA-F0-9]{64}\s+\*?.+$/.test(l.trim()));
if (!ok) throw new Error('Malformed checksum manifest'); Type guard
const isValidChecksumLine = (line) => /^[a-fA-F0-9]{64}\s+\*?.+$/.test(line.trim()); Try / catch
try { parseChecksumManifest(text); } catch (e) { if (e.message.includes("Invalid checksum manifest line")) { console.error("Regenerate with: sha256sum dist/* > SHASUMS256.txt"); } else throw e; } Prevention
- Generate manifests only with sha256sum/shasum -a 256
- Keep manifests free of headers and comments
- Validate the manifest in CI right after generation
When it happens
Trigger: A checksums manifest (SHASUMS file) contains a line that isn't `<64-hex> <filename>` — e.g. truncated hash, MD5/SHA-1 length, blank delimiter, or extra annotation text.
Common situations: Manifest generated with a non-sha256 tool; editor mangled the file; a header/comment line added to the manifest; checksums generated for a different digest algorithm.
Understand the failure class
Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.
Related errors
- Invalid checksum manifest line
- checksum manifest is missing
- Checksum manifest is missing
- Checksum manifest is missing
- Codewhale terminal receipt omitted a valid
AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15).
Data as JSON: /api/errors/4aa39cdb3e89a393.
Report an issue: GitHub.
Appendix: source
Thrown at npm/codewhale/scripts/verify-release-assets.js:319
const tagSha = await resolveTagCommitSha(repo, tag);
const release = await githubApi(repo, `/releases/tags/${encodeURIComponent(tag)}`);
const run = await findReleaseWorkflowRun(repo, tag, tagSha);
assertReleaseAssetsFresh(release, expectedAssets, run);
console.log(
`GitHub release asset freshness OK: ${expectedAssets.length} release assets for ${tag} were produced by run ${run.database_id || run.id} at ${tagSha.slice(0, 12)}.`,
);
}
function parseChecksumManifest(text) {
const checksums = new Map();
for (const line of text.split(/\r?\n/)) {
const trimmed = line.trim();
if (!trimmed) {
continue;
}
const match = trimmed.match(/^([a-fA-F0-9]{64})\s+\*?(.+)$/);
if (!match) {
throw new Error(`Invalid checksum manifest line: ${trimmed}`);
}
checksums.set(match[2], match[1].toLowerCase());
}
return checksums;
}
function assertChecksumManifestIncludes(checksums, expectedAssets, label) {
const missing = expectedAssets.filter((asset) => !checksums.has(asset));
if (missing.length > 0) {
throw new Error(`${label} is missing ${missing.join(", ")}`);
}
}
async function run() {
const version = resolveBinaryVersion();
const repo = resolveRepo();
const cnbMirror = usesCnbMirror();
const assets = cnbMirror ? CNB_RELEASE_ASSET_NAMES : allReleaseAssetNames();View on GitHub (pinned to 433685b202)