hashicorp/terraform · error

registry response includes invalid SHASUMS URL: must use…

Error message

registry response includes invalid SHASUMS URL: must use http or https scheme

What it means

Thrown when the resolved SHASUMS URL's scheme is neither http nor https. The URL is resolved against the request URL before the scheme check.

Solutions

  1. Serve the SHA256SUMS file over http(s) on the registry/mirror
  2. Ensure shasums_url is an absolute http(s) URL
  3. Report a non-http(s) scheme as a registry defect
Defensive patterns

Strategy: validation

Validate before calling

u, err := url.Parse(body.SHA256SumsURL)
if err != nil {
    return err
}
if u.Scheme != "http" && u.Scheme != "https" {
    return fmt.Errorf("shasums_url must be http(s), got %q", u.Scheme)
}

Type guard

func IsHTTPURL(s string) bool {
    u, err := url.Parse(s)
    return err == nil && (u.Scheme == "http" || u.Scheme == "https")
}

Try / catch

if shasumsURL.Scheme != "http" && shasumsURL.Scheme != "https" {
    return fmt.Errorf("refusing non-http(s) SHASUMS URL %q", shasumsURL)
}

Prevention

When it happens

Trigger: shasumsURL.Scheme is not 'http' and not 'https' after resp.Request.URL.ResolveReference(shasumsURL).

Common situations: Registry serves shasums_url as file:// or another non-http(s) scheme; empty value resolving unexpectedly; a mirror with a misconfigured scheme.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/de63ce8e68235eff. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/registry_client.go:327

		)
	}

	var checksum [sha256.Size]byte
	_, err = hex.Decode(checksum[:], []byte(body.SHA256Sum))
	if err != nil {
		return PackageMeta{}, c.errQueryFailed(
			provider,
			fmt.Errorf("registry response includes invalid SHA256 hash %q: %s", body.SHA256Sum, err),
		)
	}

	shasumsURL, err := url.Parse(body.SHA256SumsURL)
	if err != nil {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: %s", err)
	}
	shasumsURL = resp.Request.URL.ResolveReference(shasumsURL)
	if shasumsURL.Scheme != "http" && shasumsURL.Scheme != "https" {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS URL: must use http or https scheme")
	}
	document, err := c.getFile(shasumsURL)
	if err != nil {
		return PackageMeta{}, c.errQueryFailed(
			provider,
			fmt.Errorf("failed to retrieve authentication checksums for provider: %s", err),
		)
	}
	signatureURL, err := url.Parse(body.SHA256SumsSignatureURL)
	if err != nil {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS signature URL: %s", err)
	}
	signatureURL = resp.Request.URL.ResolveReference(signatureURL)
	if signatureURL.Scheme != "http" && signatureURL.Scheme != "https" {
		return PackageMeta{}, fmt.Errorf("registry response includes invalid SHASUMS signature URL: must use http or https scheme")
	}
	signature, err := c.getFile(signatureURL)
	if err != nil {

View on GitHub (pinned to d32a084675)