Report invalid checksums in the lockfile as a parse error (#31106)

### Description
The type adapter for registry file hashes in `MODULE.bazel.lock` throws a `JsonParseException` for a string that isn't a valid SHA-256 checksum, but `BazelLockFileFunction` only caught its `JsonSyntaxException` subclass. Such a lockfile crashed Bazel with an internal error instead of failing with the usual `Failed to read and parse the MODULE.bazel.lock file` error.

### Motivation
Found while writing tests for #31101.

### Build API Changes
No

### Release Notes
RELNOTES: None

Closes #31106

COPYBARA_INTEGRATE_REVIEW=https://github.com/bazelbuild/bazel/pull/31106 from fmeum:fix-lockfile-invalid-checksum b695bd474d681dcfa791aff7f7335d561cf36feb
PiperOrigin-RevId: 981250238
Change-Id: Iecd6a6cdaa2cfdf0c7cd6a05833c8b6726621185
2 files changed
tree: 3fde096c424c600942efee2d91ce16fd7c390698
  1. .bazelci/
  2. .devcontainer/
  3. .gemini/
  4. .github/
  5. docs/
  6. examples/
  7. scripts/
  8. src/
  9. third_party/
  10. tools/
  11. .bazelrc
  12. .bazelversion
  13. .gitattributes
  14. .gitignore
  15. AGENTS.md
  16. AUTHORS
  17. bazel_downloader.cfg
  18. BUILD
  19. CHANGELOG.md
  20. CODE_OF_CONDUCT.md
  21. CODEOWNERS
  22. combine_distfiles.py
  23. combine_distfiles_to_tar.sh
  24. compile.sh
  25. CONTRIBUTING.md
  26. CONTRIBUTORS
  27. distdir.bzl
  28. extensions.bzl
  29. LICENSE
  30. maven_install.json
  31. MODULE.bazel
  32. MODULE.bazel.lock
  33. oneversion_allowlist.csv
  34. oneversion_allowlist_for_tests.csv
  35. pyproject.toml
  36. README.md
  37. repositories.bzl
  38. requirements.txt
  39. SECURITY.md
  40. verify_module_bazel_lock.sh
README.md

Bazel

{Fast, Correct} - Choose two

Build and test software of any size, quickly and reliably.

  • Speed up your builds and tests: Bazel rebuilds only what is necessary. With advanced local and distributed caching, optimized dependency analysis and parallel execution, you get fast and incremental builds.

  • One tool, multiple languages: Build and test Java, C++, Android, iOS, Go, and a wide variety of other language platforms. Bazel runs on Windows, macOS, and Linux.

  • Scalable: Bazel helps you scale your organization, codebase, and continuous integration solution. It handles codebases of any size, in multiple repositories or a huge monorepo.

  • Extensible to your needs: Easily add support for new languages and platforms with Bazel's familiar extension language. Share and re-use language rules written by the growing Bazel community.

Getting Started

Documentation

Reporting a Vulnerability

To report a security issue, please email security@bazel.build with a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue. Our vulnerability management team will respond within 3 working days of your email. If the issue is confirmed as a vulnerability, we will open a Security Advisory. This project follows a 90 day disclosure timeline.

Contributing to Bazel

See CONTRIBUTING.md

Build status