evanw/esbuild · error · Error
The "esbuild" package cannot be installed because
Error message
The "esbuild" package cannot be installed because ${os} is too outdated.
The Go compiler (which esbuild relies on) no longer supports ${os},
which means the "esbuild" binary executable can't be run. You can either:
* Update your version of macOS to one that the Go compiler supports
* Use the "esbuild-wasm" package instead of the "esbuild" package
* Build esbuild yourself using an older version of the Go compiler
What it means
During esbuild's postinstall, validateBinaryVersion() (lib/npm/node-install.ts:20) executes the native binary with --version. If that execFileSync throws AND the platform is macOS AND the error text matches /_SecTrustEvaluateWithError/, esbuild reports that the OS is too old for the Go-compiled binary. The Go toolchain (which builds esbuild's native binary) drops support for older macOS releases, so Gatekeeper's security runtime can no longer validate the binary and execution fails.
Solutions
- Update macOS to a release the current Go toolchain (and thus the esbuild binary) supports.
- Switch from the esbuild package to the esbuild-wasm package, which is pure WebAssembly and needs no native binary.
- Build esbuild from source using an older Go compiler that still targets your macOS release.
- If on CI, upgrade the macOS runner image.
Defensive patterns
Strategy: fallback
Validate before calling
// Check macOS version before installing native esbuild; prefer wasm if too old.
// (Run during setup, before depending on esbuild.)
const { execFileSync } = require('child_process')
function macosTooOldForGo(minSupported = '10.15') {
if (process.platform !== 'darwin') return false
const v = execFileSync('sw_vers', ['-productVersion']).toString().trim()
return v.localeCompare(minSupported, undefined, { numeric: true }) < 0
}
// then: install 'esbuild-wasm' instead of 'esbuild' if true Prevention
- Keep macOS (and CI runner images) on a release the current Go toolchain supports.
- Have a fallback to esbuild-wasm documented for users on old macOS.
- Detect the OS version in your own installer and choose the package accordingly.
When it happens
Trigger: Running `npm install esbuild` (or yarn/pnpm) on a macOS version older than what the bundled Go-built binary supports, where launching the binary fails with a _SecTrustEvaluateWithError security error.
Common situations: Legacy Mac hardware unable to upgrade; stale macOS CI images; corporate machines pinned to an old macOS; the notarization/Gatekeeper trust evaluation failing on an out-of-date Security framework.
Related errors
- Expected but got
- Missing hash for
- Unsupported platform
- You installed esbuild for another platform than the one…
- Cannot start service: Host version
AI-assisted analysis of evanw/esbuild@f6058f8364 (2026-08-09).
Data as JSON: /api/errors/20bd8b37de6365a7.
Report an issue: GitHub.
Appendix: source
Thrown at lib/npm/node-install.ts:45
// installed from the Snap Store. This is not a problem when you download
// the official version of node. The problem appears to be that stderr
// (i.e. file descriptor 2) isn't writable?
//
// More info:
// - https://snapcraft.io/ (what the Snap Store is)
// - https://nodejs.org/dist/ (download the official version of node)
// - https://github.com/evanw/esbuild/issues/1711#issuecomment-1027554035
//
stdio: 'pipe',
}).toString().trim()
} catch (err) {
if (os.platform() === 'darwin' && /_SecTrustEvaluateWithError/.test(err + '')) {
let os = 'this version of macOS'
try {
os = 'macOS ' + child_process.execFileSync('sw_vers', ['-productVersion']).toString().trim()
} catch {
}
throw new Error(`The "esbuild" package cannot be installed because ${os} is too outdated.
The Go compiler (which esbuild relies on) no longer supports ${os},
which means the "esbuild" binary executable can't be run. You can either:
* Update your version of macOS to one that the Go compiler supports
* Use the "esbuild-wasm" package instead of the "esbuild" package
* Build esbuild yourself using an older version of the Go compiler
`)
}
throw err
}
if (stdout !== packageJSON.version) {
throw new Error(`Expected ${JSON.stringify(packageJSON.version)} but got ${JSON.stringify(stdout)}`)
}
}
function isYarn(): boolean {
const { npm_config_user_agent } = process.envView on GitHub (pinned to f6058f8364)