{"record":{"id":"de63ce8e68235eff","repo":"hashicorp/terraform","slug":"registry-response-includes-invalid-shasums-url-mu","errorCode":null,"errorMessage":"registry response includes invalid SHASUMS URL: must use http or https scheme","messagePattern":"registry response includes invalid SHASUMS URL: must use http or https scheme","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/registry_client.go","lineNumber":327,"sourceCode":"\t\t)\n\t}\n\n\tvar checksum [sha256.Size]byte\n\t_, err = hex.Decode(checksum[:], []byte(body.SHA256Sum))\n\tif err != nil {\n\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"registry response includes invalid SHA256 hash %q: %s\", body.SHA256Sum, err),\n\t\t)\n\t}\n\n\tshasumsURL, err := url.Parse(body.SHA256SumsURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS URL: %s\", err)\n\t}\n\tshasumsURL = resp.Request.URL.ResolveReference(shasumsURL)\n\tif shasumsURL.Scheme != \"http\" && shasumsURL.Scheme != \"https\" {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS URL: must use http or https scheme\")\n\t}\n\tdocument, err := c.getFile(shasumsURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, c.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"failed to retrieve authentication checksums for provider: %s\", err),\n\t\t)\n\t}\n\tsignatureURL, err := url.Parse(body.SHA256SumsSignatureURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS signature URL: %s\", err)\n\t}\n\tsignatureURL = resp.Request.URL.ResolveReference(signatureURL)\n\tif signatureURL.Scheme != \"http\" && signatureURL.Scheme != \"https\" {\n\t\treturn PackageMeta{}, fmt.Errorf(\"registry response includes invalid SHASUMS signature URL: must use http or https scheme\")\n\t}\n\tsignature, err := c.getFile(signatureURL)\n\tif err != nil {","sourceCodeStart":309,"sourceCodeEnd":345,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/registry_client.go#L309-L345","documentation":"Thrown when the resolved SHASUMS URL's scheme is neither http nor https. The URL is resolved against the request URL before the scheme check.","triggerScenarios":"shasumsURL.Scheme is not 'http' and not 'https' after resp.Request.URL.ResolveReference(shasumsURL).","commonSituations":"Registry serves shasums_url as file:// or another non-http(s) scheme; empty value resolving unexpectedly; a mirror with a misconfigured scheme.","solutions":["Serve the SHA256SUMS file over http(s) on the registry/mirror","Ensure shasums_url is an absolute http(s) URL","Report a non-http(s) scheme as a registry defect"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"u, err := url.Parse(body.SHA256SumsURL)\nif err != nil {\n    return err\n}\nif u.Scheme != \"http\" && u.Scheme != \"https\" {\n    return fmt.Errorf(\"shasums_url must be http(s), got %q\", u.Scheme)\n}","typeGuard":"func IsHTTPURL(s string) bool {\n    u, err := url.Parse(s)\n    return err == nil && (u.Scheme == \"http\" || u.Scheme == \"https\")\n}","tryCatchPattern":"if shasumsURL.Scheme != \"http\" && shasumsURL.Scheme != \"https\" {\n    return fmt.Errorf(\"refusing non-http(s) SHASUMS URL %q\", shasumsURL)\n}","preventionTips":["Serve SHA256SUMS files over https on the registry/mirror","Treat a non-http(s) shasums_url as a registry defect"],"tags":["registry","url","scheme","shasums","provider","validation"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}