hashicorp/terraform · error

registry response includes invalid SHASUMS signature URL

Error message

registry response includes invalid SHASUMS signature URL: %s

What it means

Thrown when the registry's shasums_signature_url field cannot be parsed as a URL. This URL points to the detached GPG signature over the SHA256SUMS file.

Solutions

  1. Report the malformed shasums_signature_url to the registry operator
  2. If self-hosting, publish shasums_signature_url as an absolute http(s) URL
  3. Verify the registry endpoint returns the documented signature field
Defensive patterns

Strategy: validation

Validate before calling

if _, err := url.Parse(body.SHA256SumsSignatureURL); err != nil {
    return fmt.Errorf("registry shasums_signature_url is unparseable: %w", err)
}

Type guard

func IsParseableURL(s string) bool {
    _, err := url.Parse(s)
    return err == nil
}

Try / catch

signatureURL, err := url.Parse(body.SHA256SumsSignatureURL)
if err != nil {
    return fmt.Errorf("registry returned an invalid SHASUMS signature URL: %w", err)
}

Prevention

When it happens

Trigger: url.Parse(body.SHA256SumsSignatureURL) returned a non-nil error (control characters, unparseable scheme, etc.).

Common situations: Registry returns a malformed shasums_signature_url; field corruption in transit; a mirror that omits or rewrites the signature URL incorrectly; empty value with invalid structure.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/75f3404c418a12ca. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/registry_client.go:338

	shasumsURL, err := url.Parse(body.SHA256SumsURL)
	if err != nil {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: %s", err)
	}
	shasumsURL = resp.Request.URL.ResolveReference(shasumsURL)
	if shasumsURL.Scheme != "http" && shasumsURL.Scheme != "https" {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: must use http or https scheme")
	}
	document, err := c.getFile(shasumsURL)
	if err != nil {
		return PackageMeta{}, c.errQueryFailed(
			provider,
			fmt.Errorf("failed to retrieve authentication checksums for provider: %s", err),
		)
	}
	signatureURL, err := url.Parse(body.SHA256SumsSignatureURL)
	if err != nil {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS signature URL: %s", err)
	}
	signatureURL = resp.Request.URL.ResolveReference(signatureURL)
	if signatureURL.Scheme != "http" && signatureURL.Scheme != "https" {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS signature URL: must use http or https scheme")
	}
	signature, err := c.getFile(signatureURL)
	if err != nil {
		return PackageMeta{}, c.errQueryFailed(
			provider,
			fmt.Errorf("failed to retrieve cryptographic signature for provider: %s", err),
		)
	}

	keys := make([]SigningKey, len(body.SigningKeys.GPGPublicKeys))
	for i, key := range body.SigningKeys.GPGPublicKeys {
		keys[i] = *key
	}

View on GitHub (pinned to d32a084675)