{"record":{"id":"ca39ac616f672945","repo":"ruvnet/ruflo","slug":"failed-to-fetch-manifest-from-url-res-status","errorCode":null,"errorMessage":"Failed to fetch manifest from ${url}: ${res.status} ${res.statusText}","messagePattern":"Failed to fetch manifest from (.+?): (.+?) (.+?)","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/commands/verify.ts","lineNumber":63,"sourceCode":"  integrity: {\n    manifestHashAlgo: string;\n    manifestHash: string;\n    signatureAlgo: string;\n    publicKey: string;\n    signature: string;\n    seedDerivation: string;\n  };\n}\n\nconst DEFAULT_MANIFEST_URL = 'https://raw.githubusercontent.com/ruvnet/ruflo/{branch}/verification.md.json';\n\nasync function fetchWitness(branch: string): Promise<Witness> {\n  const url = DEFAULT_MANIFEST_URL.replace('{branch}', branch);\n  // audit_1776853149979: bare fetch had no timeout — a hung GitHub CDN would\n  // pin the verify command indefinitely. 30s is generous for a sub-MB JSON.\n  const res = await fetch(url, { signal: AbortSignal.timeout(30000) });\n  if (!res.ok) {\n    throw new Error(`Failed to fetch manifest from ${url}: ${res.status} ${res.statusText}`);\n  }\n  return await res.json() as Witness;\n}\n\nfunction loadLocalWitness(localPath: string): Witness {\n  if (!existsSync(localPath)) {\n    throw new Error(`Manifest not found: ${localPath}`);\n  }\n  return JSON.parse(readFileSync(localPath, 'utf-8')) as Witness;\n}\n\n/**\n * Locate the user's installed package root.\n *\n * The witness manifest paths are repo-relative (e.g.\n * \"v3/@claude-flow/cli/dist/src/mcp-tools/hooks-tools.js\"). For\n * end users, only the dist/ subtree ships in node_modules. We map\n * the repo path → the installed equivalent by stripping the","sourceCodeStart":45,"sourceCodeEnd":81,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/commands/verify.ts#L45-L81","documentation":"The verify command fetches the signed witness manifest (verification.md.json) from raw.githubusercontent.com for the target branch (default fix/issues-may-1-3). A non-2xx HTTP response throws with the status code and reason; the surrounding handler reports 'Could not load witness manifest: ...' and exits 1. The fetch carries a 30-second abort timeout, so hangs surface as timeout aborts, not this error.","triggerScenarios":"Passing --branch <name> for a branch that doesn't exist or lacks verification.md.json (404); GitHub raw CDN rate-limiting (403); a corporate proxy intercepting with 407/502.","commonSituations":"Verifying against an old tag whose manifest was never published; CI runners behind egress filters; regions where raw.githubusercontent.com is blocked.","solutions":["Confirm the branch exists and contains verification.md.json at its root on GitHub","Skip the network: download the manifest (or copy it from a release artifact) and pass --manifest ./verification.md.json","From the same machine, curl -I the exact URL shown in the error to distinguish 404 vs proxy vs rate-limit","If rate-limited (403), wait and retry, or use the local-manifest path in CI"],"exampleFix":"# before\nruflo verify --branch nonexistent-branch\n\n# after\ncurl -fsSL -o verification.md.json https://raw.githubusercontent.com/ruvnet/ruflo/main/verification.md.json\nruflo verify --manifest ./verification.md.json","handlingStrategy":"retry","validationCode":"const res = await fetch(manifestUrl, { signal: AbortSignal.timeout(10_000) });\nif (!res.ok) throw new Error(`manifest fetch failed: ${res.status}`);\n// pre-flight the URL yourself, or skip the network entirely with --manifest <local file>","typeGuard":null,"tryCatchPattern":"for (const branch of ['main', 'fix/issues-may-1-3']) {\n  try {\n    witness = await fetchWitness(branch);\n    break;\n  } catch (err) {\n    if (err instanceof Error && err.message.includes('Failed to fetch manifest')) continue;\n    throw err;\n  }\n}\nif (!witness) throw new Error('fall back to: ruflo verify --manifest ./verification.md.json');","preventionTips":["Pin verification to --manifest with a file fetched during CI setup, not at verify time","curl -I the exact manifest URL when adding a new branch to prove it exists","Treat 403 from raw.githubusercontent.com as rate limiting — back off or go local"],"tags":["network","cli","verification","http","github"],"backgroundTag":"http-request-failed","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}