{"record":{"id":"d771ffa1a563eb7d","repo":"BoundaryML/baml","slug":"artifact-name-url-must-use-https","errorCode":null,"errorMessage":"artifact {name} URL must use HTTPS","messagePattern":"artifact (.+?) URL must use HTTPS","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"baml_language/crates/baml_release/src/manifest.rs","lineNumber":154,"sourceCode":"    Ok(())\n}\n\nfn validate_artifacts(version: &str, artifacts: &BTreeMap<String, Artifact>) -> anyhow::Result<()> {\n    let expected: std::collections::BTreeSet<_> =\n        SUPPORTED_RELEASE_TARGETS.iter().copied().collect();\n    let actual: std::collections::BTreeSet<_> = artifacts.keys().map(String::as_str).collect();\n    if actual != expected {\n        anyhow::bail!(\"manifest for {version} has target set {actual:?}; expected {expected:?}\");\n    }\n    for (target, artifact) in artifacts {\n        validate_artifact(target, artifact)?;\n    }\n    Ok(())\n}\n\nfn validate_artifact(name: &str, artifact: &Artifact) -> anyhow::Result<()> {\n    if !artifact.url.starts_with(\"https://\") {\n        anyhow::bail!(\"artifact {name} URL must use HTTPS\");\n    }\n    validate_sha256(&artifact.sha256)?;\n    Ok(())\n}\n\nfn validate_sdk(language: &str, package: &SdkPackage) -> anyhow::Result<()> {\n    if package.registry.is_empty() || package.package.is_empty() || package.version.is_empty() {\n        anyhow::bail!(\"sdk {language} has an empty registry, package, or version\");\n    }\n    if let Some(digest) = &package.verified_package_sha256 {\n        validate_sha256(digest)\n            .map_err(|error| anyhow::anyhow!(\"sdk {language} package digest: {error}\"))?;\n    }\n    if language == \"csharp\" {\n        if package.registry != \"nuget\" || package.package != \"baml-bridge\" {\n            anyhow::bail!(\"sdk csharp must identify nuget/baml-bridge\");\n        }\n        if package.verified_package_sha256.is_none() {","sourceCodeStart":136,"sourceCodeEnd":172,"githubUrl":"https://github.com/BoundaryML/baml/blob/bd85ce9dee1463ff04d27efd20531013a4ff46c1/baml_language/crates/baml_release/src/manifest.rs#L136-L172","documentation":"Each artifact entry in the release manifest must point to an https:// URL. This guard rejects non-HTTPS download locations to prevent tampering or downgrade attacks when clients fetch release binaries.","triggerScenarios":"validate_artifact() is reached with an Artifact whose url field does not start with \"https://\" — e.g. an http:// or bare-host URL in the manifest.","commonSituations":"Authoring a manifest with a local mirror or http link; copying a URL from an internal artifact store that serves plain HTTP; forgetting the scheme entirely.","solutions":["Change the artifact URL to an https:// endpoint","If using an internal mirror, put it behind TLS and use its https URL","Re-run validate() after fixing the URL"],"exampleFix":"// before\nurl = \"http://downloads.example.com/baml-linux.tar.gz\"\n\n// after\nurl = \"https://downloads.example.com/baml-linux.tar.gz\"","handlingStrategy":"validation","validationCode":"fn assert_https(url: &str) -> Result<(), String> {\n    if url.starts_with(\"https://\") { Ok(()) } else { Err(format!(\"non-HTTPS artifact URL: {url}\")) }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always publish artifacts behind TLS endpoints","Lint manifests for http:// URLs in CI","Never hand-write URLs; copy from the release pipeline output"],"tags":["security","url","manifest"],"backgroundTag":"invalid-url-format","analyzedSha":"bd85ce9dee1463ff04d27efd20531013a4ff46c1","analyzedAt":"2026-09-12T03:38:25.718Z","contentChangedAt":"2026-09-12T03:38:25.718Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}