Hmbown/CodeWhale · error · Error

is missing

Error message

${label} is missing ${missing.join(", ")}

What it means

Checksum-manifest completeness check in verify-release-assets: one or more expected release assets are absent from the parsed SHA-256 checksum manifest. Every artifact the release claims to publish must appear in the manifest so consumers can verify downloads; a missing entry means the manifest was built from an incomplete or stale asset set.

Solutions

  1. Regenerate the checksum manifest after building all expected assets.
  2. Compare expected asset names with manifest keys and fix the naming mismatch in the release pipeline.
  3. Re-run the Release workflow so the manifest and assets are produced together.

Example fix

// before
sha256sum codewhale-linux-x64.tar.gz > SHASUMS256.txt
// after
sha256sum dist/* > SHASUMS256.txt  # includes every expected asset
Defensive patterns

Strategy: validation

Validate before calling

const missing = expectedAssets.filter(a => !manifest.has(a)); if (missing.length) console.error("Manifest missing:", missing.join(", "));

Type guard

null

Try / catch

try { run(); } catch (e) { if (e.message.includes("is missing")) { console.error("Regenerate the checksum manifest with all expected assets."); process.exit(1); } throw e; }

Prevention

When it happens

Trigger: run() parses the release (or bundle) checksum manifest and one or more expected asset names have no entry in the map.

Common situations: The manifest was generated before a new platform artifact was added; the build produced assets under renamed filenames; a partial upload produced an incomplete manifest.

Understand the failure class

Background: 'Could not be found', 'does not exist', 'not found in database': the resource-not-found family when an ID, slug, key, or URI lookup comes back empty — this error's family across 20 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15). Data as JSON: /api/errors/a10fed44a54d3338. Report an issue: GitHub.

Appendix: source

Thrown at npm/codewhale/scripts/verify-release-assets.js:329

  const checksums = new Map();
  for (const line of text.split(/\r?\n/)) {
    const trimmed = line.trim();
    if (!trimmed) {
      continue;
    }
    const match = trimmed.match(/^([a-fA-F0-9]{64})\s+\*?(.+)$/);
    if (!match) {
      throw new Error(`Invalid checksum manifest line: ${trimmed}`);
    }
    checksums.set(match[2], match[1].toLowerCase());
  }
  return checksums;
}

function assertChecksumManifestIncludes(checksums, expectedAssets, label) {
  const missing = expectedAssets.filter((asset) => !checksums.has(asset));
  if (missing.length > 0) {
    throw new Error(`${label} is missing ${missing.join(", ")}`);
  }
}

async function run() {
  const version = resolveBinaryVersion();
  const repo = resolveRepo();
  const cnbMirror = usesCnbMirror();
  const assets = cnbMirror ? CNB_RELEASE_ASSET_NAMES : allReleaseAssetNames();

  assertPackageVersionMatchesBinaryVersion(version);

  console.log(`Verifying ${assets.length} release assets for ${repo}@v${version}...`);
  if (hasReleaseBaseOverride()) {
    console.log("Skipping GitHub workflow freshness check because a release asset mirror/base URL override is set.");
  } else {
    await verifyGitHubReleaseFreshness(repo, version, assets);
  }
  for (const asset of assets) {

View on GitHub (pinned to 433685b202)