{"record":{"id":"3ecf51d6dead8a02","repo":"hashicorp/terraform","slug":"error-parsing-git-ssh-url-s","errorCode":null,"errorMessage":"error parsing Git SSH URL: %s","messagePattern":"error parsing Git SSH URL: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getmodules/moduleaddrs/detect_git.go","lineNumber":131,"sourceCode":"\t}\n\n\tuser := matched[1]\n\thost := matched[2]\n\tpath := matched[3]\n\tqidx := strings.Index(path, \"?\")\n\tif qidx == -1 {\n\t\tqidx = len(path)\n\t}\n\n\tvar u url.URL\n\tu.Scheme = \"ssh\"\n\tu.User = url.User(user)\n\tu.Host = host\n\tu.Path = path[0:qidx]\n\tif qidx < len(path) {\n\t\tq, err := url.ParseQuery(path[qidx+1:])\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"error parsing Git SSH URL: %s\", err)\n\t\t}\n\t\tu.RawQuery = q.Encode()\n\t}\n\n\treturn &u, nil\n}\n","sourceCodeStart":113,"sourceCodeEnd":138,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getmodules/moduleaddrs/detect_git.go#L113-L138","documentation":"Returned when parsing an SCP-style Git SSH URL: after splitting host/user/path, url.ParseQuery fails on the substring after '?' in the path. The constructed url.URL already has scheme/user/host/path set; only the query fragment is invalid. The %s is the ParseQuery error.","triggerScenarios":"A git SSH shorthand like 'git@host:path?bad=%%query' contains a malformed query string (unencoded characters, stray '?' or '&', bad percent-escapes).","commonSituations":"Manually appending a ref as a query without encoding; copy-paste introducing a second '?'; tools that inject broken query params into SCP-style addresses.","solutions":["Drop the query portion from SCP-style SSH addresses; use a branch/tag via the module source subdir or a separate ref mechanism instead.","URL-encode the query string if a query is genuinely needed.","Switch to the full ssh:// URL form which is parsed more predictably."],"exampleFix":"# before (malformed query on SCP shorthand)\nsource = \"git@github.com:org/repo?ref=fea ture\"\n\n# after\nsource = \"git::ssh://git@github.com/org/repo.git?ref=feature\"","handlingStrategy":"validation","validationCode":"// Validate the query portion of an SCP-style SSH address before handing it off.\n// func validSCPQuery(path string) error {\n//     if i := strings.IndexByte(path, '?'); i >= 0 {\n//         if _, err := url.ParseQuery(path[i+1:]); err != nil { return err }\n//     }\n//     return nil\n// }","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Avoid query strings on SCP-style shorthand addresses.","Use ssh:// URLs when you need query parameters.","URL-encode any query values you do append."],"tags":["git","ssh","url-parsing","scp"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}