{"record":{"id":"28177237df314b71","repo":"evanw/esbuild","slug":"could-not-find-json-stringify-subpath-in-archi","errorCode":null,"errorMessage":"Could not find ${JSON.stringify(subpath)} in archive","messagePattern":"Could not find (.+?) in archive","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"lib/npm/node-install.ts","lineNumber":102,"sourceCode":"function extractFileFromTarGzip(buffer: Buffer, subpath: string): Buffer {\n  try {\n    buffer = zlib.unzipSync(buffer)\n  } catch (err: any) {\n    throw new Error(`Invalid gzip data in archive: ${err && err.message || err}`)\n  }\n  let str = (i: number, n: number) => String.fromCharCode(...buffer.subarray(i, i + n)).replace(/\\0.*$/, '')\n  let offset = 0\n  subpath = `package/${subpath}`\n  while (offset < buffer.length) {\n    let name = str(offset, 100)\n    let size = parseInt(str(offset + 124, 12), 8)\n    offset += 512\n    if (!isNaN(size) && size >= 0) {\n      if (name === subpath) return buffer.subarray(offset, offset + size)\n      offset += (size + 511) & ~511\n    }\n  }\n  throw new Error(`Could not find ${JSON.stringify(subpath)} in archive`)\n}\n\nfunction installUsingNPM(pkg: string, subpath: string, binPath: string): void {\n  // Erase \"npm_config_global\" so that \"npm install --global esbuild\" works.\n  // Otherwise this nested \"npm install\" will also be global, and the install\n  // will deadlock waiting for the global installation lock.\n  const env = { ...process.env, npm_config_global: undefined }\n\n  // Create a temporary directory inside the \"esbuild\" package with an empty\n  // \"package.json\" file. We'll use this to run \"npm install\" in.\n  const esbuildLibDir = path.dirname(require.resolve('esbuild'))\n  const installDir = path.join(esbuildLibDir, 'npm-install')\n  fs.mkdirSync(installDir)\n  try {\n    fs.writeFileSync(path.join(installDir, 'package.json'), '{}')\n\n    // Run \"npm install\" in the temporary directory which should download the\n    // desired package. Try to avoid unnecessary log output. This uses the \"npm\"","sourceCodeStart":84,"sourceCodeEnd":120,"githubUrl":"https://github.com/evanw/esbuild/blob/f6058f8364fe7ab91ca57a83e02577ed74c9cae4/lib/npm/node-install.ts#L84-L120","documentation":"In extractFileFromTarGzip (lib/npm/node-install.ts:84), after successfully decompressing the tarball the code scans tar headers looking for an entry named `package/<subpath>` (e.g. package/bin/esbuild). If no such entry exists by end of archive, it throws. This means the downloaded tarball is valid but does not contain the expected binary path.","triggerScenarios":"The @esbuild/* package tarball downloaded during the fallback path is valid gzip and a valid tar, but lacks the expected file entry (e.g. version skew where the package layout changed, or the registry served a tarball for a different version/package).","commonSituations":"Version mismatch between the esbuild JS package and the @esbuild/* platform package it tries to fetch; registry mirror caching a stale/renamed artifact; a proxy serving a similarly-named but wrong tarball.","solutions":["Ensure the esbuild package and the @esbuild/* platform package are pinned to the same version.","Clear caches (npm cache clean / pnpm store prune) and reinstall.","Verify the registry mirror serves the correct, current tarball for the exact version.","Retry the install to rule out a transient mirror issue."],"exampleFix":null,"handlingStrategy":"retry","validationCode":"// Verify the expected entry exists in a fetched tarball before trusting it.\nconst tar = require('tar-stream') // or similar\nasync function hasEntry(buf, name) {\n  return new Promise(resolve => {\n    const s = tar.extract()\n    let found = false\n    s.on('entry', (h, stream, next) => {\n      if (h.name === name) found = true\n      stream.on('end', next); stream.resume()\n    })\n    s.on('finish', () => resolve(found))\n    s.end(buf)\n  })\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Pin esbuild and @esbuild/* platform packages to the exact same version.","Use a trustworthy registry mirror that serves the correct tarball.","Clear caches when switching esbuild versions."],"tags":["install","download","registry","version-mismatch","tarball"],"backgroundTag":null,"analyzedSha":"f6058f8364fe7ab91ca57a83e02577ed74c9cae4","analyzedAt":"2026-08-09T18:37:22.223Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}