hashicorp/terraform · error
registry response includes invalid SHASUMS URL: must use…
Error message
registry response includes invalid SHASUMS URL: must use http or https scheme
What it means
Thrown when the resolved SHASUMS URL's scheme is neither http nor https. The URL is resolved against the request URL before the scheme check.
Solutions
- Serve the SHA256SUMS file over http(s) on the registry/mirror
- Ensure shasums_url is an absolute http(s) URL
- Report a non-http(s) scheme as a registry defect
Defensive patterns
Strategy: validation
Validate before calling
u, err := url.Parse(body.SHA256SumsURL)
if err != nil {
return err
}
if u.Scheme != "http" && u.Scheme != "https" {
return fmt.Errorf("shasums_url must be http(s), got %q", u.Scheme)
} Type guard
func IsHTTPURL(s string) bool {
u, err := url.Parse(s)
return err == nil && (u.Scheme == "http" || u.Scheme == "https")
} Try / catch
if shasumsURL.Scheme != "http" && shasumsURL.Scheme != "https" {
return fmt.Errorf("refusing non-http(s) SHASUMS URL %q", shasumsURL)
} Prevention
- Serve SHA256SUMS files over https on the registry/mirror
- Treat a non-http(s) shasums_url as a registry defect
When it happens
Trigger: shasumsURL.Scheme is not 'http' and not 'https' after resp.Request.URL.ResolveReference(shasumsURL).
Common situations: Registry serves shasums_url as file:// or another non-http(s) scheme; empty value resolving unexpectedly; a mirror with a misconfigured scheme.
Related errors
- registry response includes invalid download URL: must use…
- registry response includes invalid SHASUMS signature URL
- registry response includes invalid SHASUMS URL
- registry response includes invalid download URL
- failed to retrieve authentication checksums for provider
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/de63ce8e68235eff.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/registry_client.go:327
)
}
var checksum [sha256.Size]byte
_, err = hex.Decode(checksum[:], []byte(body.SHA256Sum))
if err != nil {
return PackageMeta{}, c.errQueryFailed(
provider,
fmt.Errorf("registry response includes invalid SHA256 hash %q: %s", body.SHA256Sum, err),
)
}
shasumsURL, err := url.Parse(body.SHA256SumsURL)
if err != nil {
return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: %s", err)
}
shasumsURL = resp.Request.URL.ResolveReference(shasumsURL)
if shasumsURL.Scheme != "http" && shasumsURL.Scheme != "https" {
return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: must use http or https scheme")
}
document, err := c.getFile(shasumsURL)
if err != nil {
return PackageMeta{}, c.errQueryFailed(
provider,
fmt.Errorf("failed to retrieve authentication checksums for provider: %s", err),
)
}
signatureURL, err := url.Parse(body.SHA256SumsSignatureURL)
if err != nil {
return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS signature URL: %s", err)
}
signatureURL = resp.Request.URL.ResolveReference(signatureURL)
if signatureURL.Scheme != "http" && signatureURL.Scheme != "https" {
return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS signature URL: must use http or https scheme")
}
signature, err := c.getFile(signatureURL)
if err != nil {View on GitHub (pinned to d32a084675)