{"record":{"id":"e6f19e335545436a","repo":"evanw/esbuild","slug":"missing-hash-for-key","errorCode":null,"errorMessage":"Missing hash for \"${key}\"","messagePattern":"Missing hash for \"(.+?)\"","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"lib/npm/node-install.ts","lineNumber":232,"sourceCode":"      // executable instead of a JavaScript file.\n      isToPathJS = false\n\n      // If this install script is being re-run, then \"renameSync\" will fail\n      // since the underlying inode is the same (it just returns without doing\n      // anything, and without throwing an error). In that case we should remove\n      // the file manually.\n      fs.unlinkSync(tempPath)\n    } catch {\n      // Ignore errors here since this optimization is optional\n    }\n  }\n}\n\nfunction binaryIntegrityCheck(pkg: string, subpath: string, bytes: Uint8Array): void {\n  const hash = crypto.createHash('sha256').update(bytes).digest('hex')\n  const key = `${pkg}/${subpath}`\n  const expected = packageJSON['esbuild.binaryHashes'][key]\n  if (!expected) throw new Error(`Missing hash for \"${key}\"`)\n  if (hash !== expected) throw new Error(`\"${hash.slice(0, 8)}...\" doesn't match \"${expected.slice(0, 8)}...\" for \"${pkg}\"`)\n}\n\nasync function downloadDirectlyFromNPM(pkg: string, subpath: string, binPath: string): Promise<void> {\n  // If that fails, the user could have npm configured incorrectly or could not\n  // have npm installed. Try downloading directly from npm as a last resort.\n  const url = `https://registry.npmjs.org/${pkg}/-/${pkg.replace('@esbuild/', '')}-${packageJSON.version}.tgz`\n  console.error(`[esbuild] Trying to download ${JSON.stringify(url)}`)\n  try {\n    const bytes = extractFileFromTarGzip(await fetch(url), subpath)\n    binaryIntegrityCheck(pkg, subpath, bytes)\n    fs.writeFileSync(binPath, bytes)\n    fs.chmodSync(binPath, 0o755)\n  } catch (e: any) {\n    console.error(`[esbuild] Failed to download ${JSON.stringify(url)}: ${e && e.message || e}`)\n    throw e\n  }\n}","sourceCodeStart":214,"sourceCodeEnd":250,"githubUrl":"https://github.com/evanw/esbuild/blob/f6058f8364fe7ab91ca57a83e02577ed74c9cae4/lib/npm/node-install.ts#L214-L250","documentation":"binaryIntegrityCheck (lib/npm/node-install.ts:228) computes a sha256 of the downloaded binary and looks up the expected hash in packageJSON['esbuild.binaryHashes'] under the key `${pkg}/${subpath}`. If there is no entry for that key at all, it throws 'Missing hash'. This indicates the downloaded platform binary does not correspond to anything the JS package knows about, i.e. a pkg/subpath combination the shipping esbuild release never recorded.","triggerScenarios":"A platform package binary (e.g. @esbuild/linux-x64/bin/esbuild) is fetched whose pkg/subpath key is absent from the esbuild package.json's esbuild.binaryHashes table, so its integrity cannot be verified.","commonSituations":"Version drift between the esbuild JS package and the @esbuild/* native package; a manually substituted or renamed platform package; a package.json that was modified or corrupted; an internal/fork platform package not in the hash table.","solutions":["Reinstall so the esbuild JS package and its @esbuild/* native packages come from the same release.","Remove any hand-edited or forked platform packages from node_modules.","Clear the package cache and reinstall.","If you maintain a fork, ensure your package.json's esbuild.binaryHashes includes the forked key."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Confirm the platform key exists in the shipped hash table before installing.\nconst { 'esbuild.binaryHashes': hashes, version } = require('esbuild/package.json')\nfunction assertHashExists(pkg, subpath) {\n  const key = `${pkg}/${subpath}`\n  if (!hashes[key]) {\n    throw new Error(`No integrity hash for ${key}; esbuild/js version skew (${version})`)\n  }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Keep the esbuild JS package and platform packages version-aligned.","Do not hand-edit package.json's esbuild.binaryHashes.","Reinstall cleanly after any esbuild upgrade."],"tags":["install","integrity","version-mismatch","native-binary"],"backgroundTag":null,"analyzedSha":"f6058f8364fe7ab91ca57a83e02577ed74c9cae4","analyzedAt":"2026-08-09T18:37:22.223Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}