hashicorp/terraform · error
registry response includes invalid download URL: must use…
Error message
registry response includes invalid download URL: must use http or https scheme
What it means
Thrown when the resolved download URL's scheme is neither http nor https. The download URL is resolved against the request URL first, so a relative path against an https base normally yields https; this fires when the absolute scheme is file/data/javascript/etc.
Solutions
- Ensure the registry serves download_url over http(s) only
- If self-hosting, publish artifacts behind an https endpoint
- Report a non-http(s) download_url as a registry defect
Defensive patterns
Strategy: validation
Validate before calling
u, err := url.Parse(body.DownloadURL)
if err != nil {
return err
}
if u.Scheme != "http" && u.Scheme != "https" {
return fmt.Errorf("download_url must be http(s), got %q", u.Scheme)
} Type guard
func IsHTTPURL(s string) bool {
u, err := url.Parse(s)
return err == nil && (u.Scheme == "http" || u.Scheme == "https")
} Try / catch
if downloadURL.Scheme != "http" && downloadURL.Scheme != "https" {
return fmt.Errorf("refusing non-http(s) download URL %q", downloadURL)
} Prevention
- Serve provider artifacts over https only
- Treat file:// or data: download URLs as a registry defect
When it happens
Trigger: downloadURL.Scheme is not 'http' and not 'https' after resp.Request.URL.ResolveReference(downloadURL).
Common situations: Registry returns a file:// URL; download_url is empty and resolves to the base with no path producing an unexpected scheme; a mirror serving data: URIs; SSRF-hardening failure on the registry side.
Related errors
- registry response includes invalid download URL
- registry response includes invalid SHASUMS URL: must use…
- registry response includes invalid SHASUMS signature URL
- registry response includes invalid SHASUMS URL
- registry response includes invalid SHA256 hash
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/f7701ff7e9f01961.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/registry_client.go:289
if err != nil {
return PackageMeta{}, err
}
protoErr.Suggestion = closest
return PackageMeta{}, protoErr
}
}
if body.OS != target.OS || body.Arch != target.Arch {
return PackageMeta{}, fmt.Errorf("registry response to request for %s archive has incorrect target %s", target, Platform{body.OS, body.Arch})
}
downloadURL, err := url.Parse(body.DownloadURL)
if err != nil {
return PackageMeta{}, fmt.Errorf("registry response includes invalid download URL: %s", err)
}
downloadURL = resp.Request.URL.ResolveReference(downloadURL)
if downloadURL.Scheme != "http" && downloadURL.Scheme != "https" {
return PackageMeta{}, fmt.Errorf("registry response includes invalid download URL: must use http or https scheme")
}
ret := PackageMeta{
Provider: provider,
Version: version,
ProtocolVersions: protoVersions,
TargetPlatform: Platform{
OS: body.OS,
Arch: body.Arch,
},
Filename: body.Filename,
Location: PackageHTTPURL(downloadURL.String()),
// "Authentication" is populated below
}
if len(body.SHA256Sum) != sha256.Size*2 { // *2 because it's hex-encoded
return PackageMeta{}, c.errQueryFailed(
provider,View on GitHub (pinned to d32a084675)