{"record":{"id":"d2271aeb87c82781","repo":"hashicorp/terraform","slug":"registry-response-includes-invalid-shasums-url-s","errorCode":null,"errorMessage":"registry response includes invalid SHASUMS URL: %s","messagePattern":"registry response includes invalid SHASUMS URL: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/registry_client.go","lineNumber":323,"sourceCode":"\tif len(body.SHA256Sum) != sha256.Size*2 { // *2 because it's hex-encoded\n\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"registry response includes invalid SHA256 hash %q: %s\", body.SHA256Sum, err),\n\t\t)\n\t}\n\n\tvar checksum [sha256.Size]byte\n\t_, err = hex.Decode(checksum[:], []byte(body.SHA256Sum))\n\tif err != nil {\n\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"registry response includes invalid SHA256 hash %q: %s\", body.SHA256Sum, err),\n\t\t)\n\t}\n\n\tshasumsURL, err := url.Parse(body.SHA256SumsURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS URL: %s\", err)\n\t}\n\tshasumsURL = resp.Request.URL.ResolveReference(shasumsURL)\n\tif shasumsURL.Scheme != \"http\" && shasumsURL.Scheme != \"https\" {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS URL: must use http or https scheme\")\n\t}\n\tdocument, err := c.getFile(shasumsURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"failed to retrieve authentication checksums for provider: %s\", err),\n\t\t)\n\t}\n\tsignatureURL, err := url.Parse(body.SHA256SumsSignatureURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS signature URL: %s\", err)\n\t}\n\tsignatureURL = resp.Request.URL.ResolveReference(signatureURL)\n\tif signatureURL.Scheme != \"http\" && signatureURL.Scheme != \"https\" {","sourceCodeStart":305,"sourceCodeEnd":341,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/registry_client.go#L305-L341","documentation":"Thrown when the registry's shasums_url field cannot be parsed as a URL. This URL points to the SHA256SUMS file used for checksum authentication.","triggerScenarios":"url.Parse(body.SHA256SumsURL) returned a non-nil error (control characters, unparseable scheme, etc.).","commonSituations":"Registry returns a malformed shasums_url; field corruption in transit; a mirror rewriting the field incorrectly; empty or whitespace value with invalid structure.","solutions":["Report the malformed shasums_url to the registry operator","If self-hosting, publish shasums_url as an absolute http(s) URL","Verify the registry endpoint returns the documented field"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"if _, err := url.Parse(body.SHA256SumsURL); err != nil {\n    return fmt.Errorf(\"registry shasums_url is unparseable: %w\", err)\n}","typeGuard":"func IsParseableURL(s string) bool {\n    _, err := url.Parse(s)\n    return err == nil\n}","tryCatchPattern":"shasumsURL, err := url.Parse(body.SHA256SumsURL)\nif err != nil {\n    return fmt.Errorf(\"registry returned an invalid SHASUMS URL: %w\", err)\n}","preventionTips":["Publish shasums_url as an absolute http(s) URL on the registry","Sanitize response fields of control characters"],"tags":["registry","url","shasums","provider","validation"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}