Hmbown/CodeWhale · error · NonRetryableError
checksum manifest is missing
Error message
${label} checksum manifest is missing ${missing.join(", ")} What it means
Before downloading, the installer validates that the label's (e.g. the chosen release source's) checksum manifest contains entries for every required asset, collecting all missing names and throwing one aggregated NonRetryableError listing them. This fails fast instead of discovering missing digests mid-verification.
Solutions
- Use the official GitHub Release source (unset CODEWHALE_RELEASE_BASE_URL / CODEWHALE_USE_CNB_MIRROR) whose manifest is complete.
- If you run the mirror, regenerate SHA256SUMS to include every required asset listed in the error.
- Only require assets for the current platform by running the installer on a supported target, or upgrade the installer/mirror to matching versions.
- Pick a different complete mirror via CODEWHALE_RELEASE_BASE_URL.
Example fix
// before (partial mirror manifest) codewhale-linux-x64.tar.gz <hash> // after (manifest covers all required assets) codewhale-linux-x64.tar.gz <hash> codewhale-linux-arm64.tar.gz <hash> codewhale-darwin-x64.tar.gz <hash> codewhale-darwin-arm64.tar.gz <hash> codewhale-win32-x64.zip <hash>
Defensive patterns
Strategy: validation
Validate before calling
const missing = requiredAssets.filter(a => !checksums.has(a));
if (missing.length) throw new Error(`Manifest incomplete, missing: ${missing.join(', ')}`); Try / catch
try {
await install();
} catch (err) {
if (err.message.includes('checksum manifest is missing')) {
// switch to the official source or complete the mirror's manifest
} else throw err;
} Prevention
- Only use mirrors that publish complete SHA256SUMS files.
- Keep installer and mirror versions in sync so required asset lists match.
- Fail fast in CI: validate manifest completeness before the install step.
When it happens
Trigger: A selected source's fetched manifest lacks one or more assets in the `requiredAssets` list — typically a partial or stale SHA256SUMS on a custom mirror, or a new asset added by the installer that an older mirror's manifest predates.
Common situations: Third-party CODEWHALE_RELEASE_BASE_URL mirrors that only republish a subset of assets; installer upgraded to require a new platform artifact the mirror has never hosted; locked/pinned manifest older than the current release's asset set.
Understand the failure class
Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.
Related errors
- Invalid checksum manifest line
- Checksum manifest is missing
- Checksum manifest is missing
- Checksum mismatch for
- Invalid checksum manifest line
AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15).
Data as JSON: /api/errors/b6c8f57840113112.
Report an issue: GitHub.
Appendix: source
Thrown at npm/codewhale/scripts/install.js:1224
`version=${version}`,
"",
].join("\n");
}
async function writeSourceReceipt(targetPath, source, version) {
await writeFile(`${targetPath}.source`, formatSourceReceipt(source, version), "utf8");
}
function assertManifestHasAssets(checksums, requiredAssets, label) {
const missing = [];
for (let i = 0; i < requiredAssets.length; i += 1) {
const asset = requiredAssets[i];
if (!checksums.has(asset)) {
missing.push(asset);
}
}
if (missing.length > 0) {
throw new NonRetryableError(
`${label} checksum manifest is missing ${missing.join(", ")}`,
);
}
}
async function fetchChecksumManifest(url, options) {
const fetchText = options.fetchText || downloadText;
const text = await fetchText(url, {
context: options.context,
signal: options.signal,
totalTimeoutMs:
options.totalTimeoutMs === undefined || options.totalTimeoutMs === null
? MANIFEST_TIMEOUT_MS
: options.totalTimeoutMs,
stallMs:
options.stallMs === undefined || options.stallMs === null
? MANIFEST_STALL_MS
: options.stallMs,View on GitHub (pinned to 433685b202)