Hmbown/CodeWhale · error · Error

Invalid checksum manifest line

Error message

Invalid checksum manifest line: ${trimmed}

What it means

parseChecksumManifest parses a SHA-256 checksums file line by line; each non-empty line must match /^([a-fA-F0-9]{64})\s+\*?(.+)$/ (64 hex chars, whitespace, filename). Lines that don't match throw this error.

Solutions

  1. Regenerate the manifest with sha256sum: `sha256sum dist/* > SHASUMS256.txt`.
  2. Open the manifest and fix or remove the offending line.
  3. Ensure no comments/headers are present — only checksum lines are allowed.

Example fix

// before
abc123  dist/codewhale.tgz
// after
9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08  dist/codewhale.tgz
Defensive patterns

Strategy: validation

Validate before calling

const ok = require('fs').readFileSync('SHASUMS256.txt','utf8').split('\n').filter(Boolean).every(l => /^[a-fA-F0-9]{64}\s+\*?.+$/.test(l.trim()));
if (!ok) throw new Error('Malformed checksum manifest');

Type guard

const isValidChecksumLine = (line) => /^[a-fA-F0-9]{64}\s+\*?.+$/.test(line.trim());

Try / catch

try { parseChecksumManifest(text); } catch (e) { if (e.message.includes("Invalid checksum manifest line")) { console.error("Regenerate with: sha256sum dist/* > SHASUMS256.txt"); } else throw e; }

Prevention

When it happens

Trigger: A checksums manifest (SHASUMS file) contains a line that isn't `<64-hex> <filename>` — e.g. truncated hash, MD5/SHA-1 length, blank delimiter, or extra annotation text.

Common situations: Manifest generated with a non-sha256 tool; editor mangled the file; a header/comment line added to the manifest; checksums generated for a different digest algorithm.

Understand the failure class

Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15). Data as JSON: /api/errors/4aa39cdb3e89a393. Report an issue: GitHub.

Appendix: source

Thrown at npm/codewhale/scripts/verify-release-assets.js:319

  const tagSha = await resolveTagCommitSha(repo, tag);
  const release = await githubApi(repo, `/releases/tags/${encodeURIComponent(tag)}`);
  const run = await findReleaseWorkflowRun(repo, tag, tagSha);
  assertReleaseAssetsFresh(release, expectedAssets, run);
  console.log(
    `GitHub release asset freshness OK: ${expectedAssets.length} release assets for ${tag} were produced by run ${run.database_id || run.id} at ${tagSha.slice(0, 12)}.`,
  );
}

function parseChecksumManifest(text) {
  const checksums = new Map();
  for (const line of text.split(/\r?\n/)) {
    const trimmed = line.trim();
    if (!trimmed) {
      continue;
    }
    const match = trimmed.match(/^([a-fA-F0-9]{64})\s+\*?(.+)$/);
    if (!match) {
      throw new Error(`Invalid checksum manifest line: ${trimmed}`);
    }
    checksums.set(match[2], match[1].toLowerCase());
  }
  return checksums;
}

function assertChecksumManifestIncludes(checksums, expectedAssets, label) {
  const missing = expectedAssets.filter((asset) => !checksums.has(asset));
  if (missing.length > 0) {
    throw new Error(`${label} is missing ${missing.join(", ")}`);
  }
}

async function run() {
  const version = resolveBinaryVersion();
  const repo = resolveRepo();
  const cnbMirror = usesCnbMirror();
  const assets = cnbMirror ? CNB_RELEASE_ASSET_NAMES : allReleaseAssetNames();

View on GitHub (pinned to 433685b202)