hashicorp/terraform · error
registry response includes invalid SHASUMS signature URL
Error message
registry response includes invalid SHASUMS signature URL: %s
What it means
Thrown when the registry's shasums_signature_url field cannot be parsed as a URL. This URL points to the detached GPG signature over the SHA256SUMS file.
Solutions
- Report the malformed shasums_signature_url to the registry operator
- If self-hosting, publish shasums_signature_url as an absolute http(s) URL
- Verify the registry endpoint returns the documented signature field
Defensive patterns
Strategy: validation
Validate before calling
if _, err := url.Parse(body.SHA256SumsSignatureURL); err != nil {
return fmt.Errorf("registry shasums_signature_url is unparseable: %w", err)
} Type guard
func IsParseableURL(s string) bool {
_, err := url.Parse(s)
return err == nil
} Try / catch
signatureURL, err := url.Parse(body.SHA256SumsSignatureURL)
if err != nil {
return fmt.Errorf("registry returned an invalid SHASUMS signature URL: %w", err)
} Prevention
- Publish shasums_signature_url as an absolute http(s) URL on the registry
- Sanitize response fields of control characters
When it happens
Trigger: url.Parse(body.SHA256SumsSignatureURL) returned a non-nil error (control characters, unparseable scheme, etc.).
Common situations: Registry returns a malformed shasums_signature_url; field corruption in transit; a mirror that omits or rewrites the signature URL incorrectly; empty value with invalid structure.
Related errors
- registry response includes invalid SHASUMS URL: must use…
- registry response includes invalid SHASUMS URL
- registry response includes invalid download URL
- registry response includes invalid download URL: must use…
- failed to retrieve authentication checksums for provider
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/75f3404c418a12ca.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/registry_client.go:338
shasumsURL, err := url.Parse(body.SHA256SumsURL)
if err != nil {
return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: %s", err)
}
shasumsURL = resp.Request.URL.ResolveReference(shasumsURL)
if shasumsURL.Scheme != "http" && shasumsURL.Scheme != "https" {
return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: must use http or https scheme")
}
document, err := c.getFile(shasumsURL)
if err != nil {
return PackageMeta{}, c.errQueryFailed(
provider,
fmt.Errorf("failed to retrieve authentication checksums for provider: %s", err),
)
}
signatureURL, err := url.Parse(body.SHA256SumsSignatureURL)
if err != nil {
return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS signature URL: %s", err)
}
signatureURL = resp.Request.URL.ResolveReference(signatureURL)
if signatureURL.Scheme != "http" && signatureURL.Scheme != "https" {
return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS signature URL: must use http or https scheme")
}
signature, err := c.getFile(signatureURL)
if err != nil {
return PackageMeta{}, c.errQueryFailed(
provider,
fmt.Errorf("failed to retrieve cryptographic signature for provider: %s", err),
)
}
keys := make([]SigningKey, len(body.SigningKeys.GPGPublicKeys))
for i, key := range body.SigningKeys.GPGPublicKeys {
keys[i] = *key
}
View on GitHub (pinned to d32a084675)