{"record":{"id":"75f3404c418a12ca","repo":"hashicorp/terraform","slug":"registry-response-includes-invalid-shasums-signatu","errorCode":null,"errorMessage":"registry response includes invalid SHASUMS signature URL: %s","messagePattern":"registry response includes invalid SHASUMS signature URL: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/registry_client.go","lineNumber":338,"sourceCode":"\n\tshasumsURL, err := url.Parse(body.SHA256SumsURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS URL: %s\", err)\n\t}\n\tshasumsURL = resp.Request.URL.ResolveReference(shasumsURL)\n\tif shasumsURL.Scheme != \"http\" && shasumsURL.Scheme != \"https\" {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS URL: must use http or https scheme\")\n\t}\n\tdocument, err := c.getFile(shasumsURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"failed to retrieve authentication checksums for provider: %s\", err),\n\t\t)\n\t}\n\tsignatureURL, err := url.Parse(body.SHA256SumsSignatureURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS signature URL: %s\", err)\n\t}\n\tsignatureURL = resp.Request.URL.ResolveReference(signatureURL)\n\tif signatureURL.Scheme != \"http\" && signatureURL.Scheme != \"https\" {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS signature URL: must use http or https scheme\")\n\t}\n\tsignature, err := c.getFile(signatureURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"failed to retrieve cryptographic signature for provider: %s\", err),\n\t\t)\n\t}\n\n\tkeys := make([]SigningKey, len(body.SigningKeys.GPGPublicKeys))\n\tfor i, key := range body.SigningKeys.GPGPublicKeys {\n\t\tkeys[i] = *key\n\t}\n","sourceCodeStart":320,"sourceCodeEnd":356,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/registry_client.go#L320-L356","documentation":"Thrown when the registry's shasums_signature_url field cannot be parsed as a URL. This URL points to the detached GPG signature over the SHA256SUMS file.","triggerScenarios":"url.Parse(body.SHA256SumsSignatureURL) returned a non-nil error (control characters, unparseable scheme, etc.).","commonSituations":"Registry returns a malformed shasums_signature_url; field corruption in transit; a mirror that omits or rewrites the signature URL incorrectly; empty value with invalid structure.","solutions":["Report the malformed shasums_signature_url to the registry operator","If self-hosting, publish shasums_signature_url as an absolute http(s) URL","Verify the registry endpoint returns the documented signature field"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"if _, err := url.Parse(body.SHA256SumsSignatureURL); err != nil {\n    return fmt.Errorf(\"registry shasums_signature_url is unparseable: %w\", err)\n}","typeGuard":"func IsParseableURL(s string) bool {\n    _, err := url.Parse(s)\n    return err == nil\n}","tryCatchPattern":"signatureURL, err := url.Parse(body.SHA256SumsSignatureURL)\nif err != nil {\n    return fmt.Errorf(\"registry returned an invalid SHASUMS signature URL: %w\", err)\n}","preventionTips":["Publish shasums_signature_url as an absolute http(s) URL on the registry","Sanitize response fields of control characters"],"tags":["registry","url","signature","shasums","provider","validation"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}