{"record":{"id":"4aa39cdb3e89a393","repo":"Hmbown/CodeWhale","slug":"invalid-checksum-manifest-line-trimmed-verify-release-assets","errorCode":null,"errorMessage":"Invalid checksum manifest line: ${trimmed}","messagePattern":"Invalid checksum manifest line: (.+?)","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"npm/codewhale/scripts/verify-release-assets.js","lineNumber":319,"sourceCode":"  const tagSha = await resolveTagCommitSha(repo, tag);\n  const release = await githubApi(repo, `/releases/tags/${encodeURIComponent(tag)}`);\n  const run = await findReleaseWorkflowRun(repo, tag, tagSha);\n  assertReleaseAssetsFresh(release, expectedAssets, run);\n  console.log(\n    `GitHub release asset freshness OK: ${expectedAssets.length} release assets for ${tag} were produced by run ${run.database_id || run.id} at ${tagSha.slice(0, 12)}.`,\n  );\n}\n\nfunction parseChecksumManifest(text) {\n  const checksums = new Map();\n  for (const line of text.split(/\\r?\\n/)) {\n    const trimmed = line.trim();\n    if (!trimmed) {\n      continue;\n    }\n    const match = trimmed.match(/^([a-fA-F0-9]{64})\\s+\\*?(.+)$/);\n    if (!match) {\n      throw new Error(`Invalid checksum manifest line: ${trimmed}`);\n    }\n    checksums.set(match[2], match[1].toLowerCase());\n  }\n  return checksums;\n}\n\nfunction assertChecksumManifestIncludes(checksums, expectedAssets, label) {\n  const missing = expectedAssets.filter((asset) => !checksums.has(asset));\n  if (missing.length > 0) {\n    throw new Error(`${label} is missing ${missing.join(\", \")}`);\n  }\n}\n\nasync function run() {\n  const version = resolveBinaryVersion();\n  const repo = resolveRepo();\n  const cnbMirror = usesCnbMirror();\n  const assets = cnbMirror ? CNB_RELEASE_ASSET_NAMES : allReleaseAssetNames();","sourceCodeStart":301,"sourceCodeEnd":337,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/433685b2024e7bc4c99e1e2e326bcad39b4d9d65/npm/codewhale/scripts/verify-release-assets.js#L301-L337","documentation":"parseChecksumManifest parses a SHA-256 checksums file line by line; each non-empty line must match /^([a-fA-F0-9]{64})\\s+\\*?(.+)$/ (64 hex chars, whitespace, filename). Lines that don't match throw this error.","triggerScenarios":"A checksums manifest (SHASUMS file) contains a line that isn't `<64-hex> <filename>` — e.g. truncated hash, MD5/SHA-1 length, blank delimiter, or extra annotation text.","commonSituations":"Manifest generated with a non-sha256 tool; editor mangled the file; a header/comment line added to the manifest; checksums generated for a different digest algorithm.","solutions":["Regenerate the manifest with sha256sum: `sha256sum dist/* > SHASUMS256.txt`.","Open the manifest and fix or remove the offending line.","Ensure no comments/headers are present — only checksum lines are allowed."],"exampleFix":"// before\nabc123  dist/codewhale.tgz\n// after\n9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08  dist/codewhale.tgz","handlingStrategy":"validation","validationCode":"const ok = require('fs').readFileSync('SHASUMS256.txt','utf8').split('\\n').filter(Boolean).every(l => /^[a-fA-F0-9]{64}\\s+\\*?.+$/.test(l.trim()));\nif (!ok) throw new Error('Malformed checksum manifest');","typeGuard":"const isValidChecksumLine = (line) => /^[a-fA-F0-9]{64}\\s+\\*?.+$/.test(line.trim());","tryCatchPattern":"try { parseChecksumManifest(text); } catch (e) { if (e.message.includes(\"Invalid checksum manifest line\")) { console.error(\"Regenerate with: sha256sum dist/* > SHASUMS256.txt\"); } else throw e; }","preventionTips":["Generate manifests only with sha256sum/shasum -a 256","Keep manifests free of headers and comments","Validate the manifest in CI right after generation"],"tags":["checksum","sha256","manifest","validation"],"backgroundTag":"invalid-argument-format","analyzedSha":"433685b2024e7bc4c99e1e2e326bcad39b4d9d65","analyzedAt":"2026-09-15T12:24:24.634Z","contentChangedAt":"2026-09-15T12:24:24.634Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}