evanw/esbuild · error · Error

The "esbuild" package cannot be installed because

Error message

The "esbuild" package cannot be installed because ${os} is too outdated.

The Go compiler (which esbuild relies on) no longer supports ${os},
which means the "esbuild" binary executable can't be run. You can either:

  * Update your version of macOS to one that the Go compiler supports
  * Use the "esbuild-wasm" package instead of the "esbuild" package
  * Build esbuild yourself using an older version of the Go compiler

What it means

During esbuild's postinstall, validateBinaryVersion() (lib/npm/node-install.ts:20) executes the native binary with --version. If that execFileSync throws AND the platform is macOS AND the error text matches /_SecTrustEvaluateWithError/, esbuild reports that the OS is too old for the Go-compiled binary. The Go toolchain (which builds esbuild's native binary) drops support for older macOS releases, so Gatekeeper's security runtime can no longer validate the binary and execution fails.

Solutions

  1. Update macOS to a release the current Go toolchain (and thus the esbuild binary) supports.
  2. Switch from the esbuild package to the esbuild-wasm package, which is pure WebAssembly and needs no native binary.
  3. Build esbuild from source using an older Go compiler that still targets your macOS release.
  4. If on CI, upgrade the macOS runner image.
Defensive patterns

Strategy: fallback

Validate before calling

// Check macOS version before installing native esbuild; prefer wasm if too old.
// (Run during setup, before depending on esbuild.)
const { execFileSync } = require('child_process')
function macosTooOldForGo(minSupported = '10.15') {
  if (process.platform !== 'darwin') return false
  const v = execFileSync('sw_vers', ['-productVersion']).toString().trim()
  return v.localeCompare(minSupported, undefined, { numeric: true }) < 0
}
// then: install 'esbuild-wasm' instead of 'esbuild' if true

Prevention

When it happens

Trigger: Running `npm install esbuild` (or yarn/pnpm) on a macOS version older than what the bundled Go-built binary supports, where launching the binary fails with a _SecTrustEvaluateWithError security error.

Common situations: Legacy Mac hardware unable to upgrade; stale macOS CI images; corporate machines pinned to an old macOS; the notarization/Gatekeeper trust evaluation failing on an out-of-date Security framework.

Related errors


AI-assisted analysis of evanw/esbuild@f6058f8364 (2026-08-09). Data as JSON: /api/errors/20bd8b37de6365a7. Report an issue: GitHub.

Appendix: source

Thrown at lib/npm/node-install.ts:45

      // installed from the Snap Store. This is not a problem when you download
      // the official version of node. The problem appears to be that stderr
      // (i.e. file descriptor 2) isn't writable?
      //
      // More info:
      // - https://snapcraft.io/ (what the Snap Store is)
      // - https://nodejs.org/dist/ (download the official version of node)
      // - https://github.com/evanw/esbuild/issues/1711#issuecomment-1027554035
      //
      stdio: 'pipe',
    }).toString().trim()
  } catch (err) {
    if (os.platform() === 'darwin' && /_SecTrustEvaluateWithError/.test(err + '')) {
      let os = 'this version of macOS'
      try {
        os = 'macOS ' + child_process.execFileSync('sw_vers', ['-productVersion']).toString().trim()
      } catch {
      }
      throw new Error(`The "esbuild" package cannot be installed because ${os} is too outdated.

The Go compiler (which esbuild relies on) no longer supports ${os},
which means the "esbuild" binary executable can't be run. You can either:

  * Update your version of macOS to one that the Go compiler supports
  * Use the "esbuild-wasm" package instead of the "esbuild" package
  * Build esbuild yourself using an older version of the Go compiler
`)
    }
    throw err
  }
  if (stdout !== packageJSON.version) {
    throw new Error(`Expected ${JSON.stringify(packageJSON.version)} but got ${JSON.stringify(stdout)}`)
  }
}

function isYarn(): boolean {
  const { npm_config_user_agent } = process.env

View on GitHub (pinned to f6058f8364)