evanw/esbuild · error · Error

Missing hash for

Error message

Missing hash for "${key}"

What it means

binaryIntegrityCheck (lib/npm/node-install.ts:228) computes a sha256 of the downloaded binary and looks up the expected hash in packageJSON['esbuild.binaryHashes'] under the key `${pkg}/${subpath}`. If there is no entry for that key at all, it throws 'Missing hash'. This indicates the downloaded platform binary does not correspond to anything the JS package knows about, i.e. a pkg/subpath combination the shipping esbuild release never recorded.

Solutions

  1. Reinstall so the esbuild JS package and its @esbuild/* native packages come from the same release.
  2. Remove any hand-edited or forked platform packages from node_modules.
  3. Clear the package cache and reinstall.
  4. If you maintain a fork, ensure your package.json's esbuild.binaryHashes includes the forked key.
Defensive patterns

Strategy: validation

Validate before calling

// Confirm the platform key exists in the shipped hash table before installing.
const { 'esbuild.binaryHashes': hashes, version } = require('esbuild/package.json')
function assertHashExists(pkg, subpath) {
  const key = `${pkg}/${subpath}`
  if (!hashes[key]) {
    throw new Error(`No integrity hash for ${key}; esbuild/js version skew (${version})`)
  }
}

Prevention

When it happens

Trigger: A platform package binary (e.g. @esbuild/linux-x64/bin/esbuild) is fetched whose pkg/subpath key is absent from the esbuild package.json's esbuild.binaryHashes table, so its integrity cannot be verified.

Common situations: Version drift between the esbuild JS package and the @esbuild/* native package; a manually substituted or renamed platform package; a package.json that was modified or corrupted; an internal/fork platform package not in the hash table.

Related errors


AI-assisted analysis of evanw/esbuild@f6058f8364 (2026-08-09). Data as JSON: /api/errors/e6f19e335545436a. Report an issue: GitHub.

Appendix: source

Thrown at lib/npm/node-install.ts:232

      // executable instead of a JavaScript file.
      isToPathJS = false

      // If this install script is being re-run, then "renameSync" will fail
      // since the underlying inode is the same (it just returns without doing
      // anything, and without throwing an error). In that case we should remove
      // the file manually.
      fs.unlinkSync(tempPath)
    } catch {
      // Ignore errors here since this optimization is optional
    }
  }
}

function binaryIntegrityCheck(pkg: string, subpath: string, bytes: Uint8Array): void {
  const hash = crypto.createHash('sha256').update(bytes).digest('hex')
  const key = `${pkg}/${subpath}`
  const expected = packageJSON['esbuild.binaryHashes'][key]
  if (!expected) throw new Error(`Missing hash for "${key}"`)
  if (hash !== expected) throw new Error(`"${hash.slice(0, 8)}..." doesn't match "${expected.slice(0, 8)}..." for "${pkg}"`)
}

async function downloadDirectlyFromNPM(pkg: string, subpath: string, binPath: string): Promise<void> {
  // If that fails, the user could have npm configured incorrectly or could not
  // have npm installed. Try downloading directly from npm as a last resort.
  const url = `https://registry.npmjs.org/${pkg}/-/${pkg.replace('@esbuild/', '')}-${packageJSON.version}.tgz`
  console.error(`[esbuild] Trying to download ${JSON.stringify(url)}`)
  try {
    const bytes = extractFileFromTarGzip(await fetch(url), subpath)
    binaryIntegrityCheck(pkg, subpath, bytes)
    fs.writeFileSync(binPath, bytes)
    fs.chmodSync(binPath, 0o755)
  } catch (e: any) {
    console.error(`[esbuild] Failed to download ${JSON.stringify(url)}: ${e && e.message || e}`)
    throw e
  }
}

View on GitHub (pinned to f6058f8364)