Node.js应用部署Heroku失败(bcrypt权限问题)求助
Hey there, I’ve dealt with this exact bcrypt permission error on Heroku before—let’s get your app deployed again!
What’s causing this?
The error sh: 1: node-pre-gyp: Permission denied happens because the old bcrypt@1.0.3 version relies on node-pre-gyp to fetch pre-built binaries, but Heroku’s sandboxed build environment has strict permissions that block this process. It’s likely Heroku updated their build environment recently, which is why your identical app worked before but fails now.
Solutions to try (ordered by recommendation):
1. Upgrade bcrypt to a newer, stable version
Old bcrypt versions have compatibility issues with modern Node.js environments (including Heroku’s). Upgrading is the most reliable fix:
- Uninstall the old version:
npm uninstall bcrypt - Install the latest stable version:
npm install bcrypt - Commit your updated
package.jsonandpackage-lock.jsonto Git, then redeploy to Heroku.
2. Force bcrypt to build from source on Heroku
If you can’t upgrade bcrypt for dependency reasons, add a post-build script to your package.json to rebuild bcrypt directly on Heroku:
Add this line to the scripts section of your package.json:
"heroku-postbuild": "npm rebuild bcrypt --build-from-source"
Commit the change and redeploy—this skips the pre-built binary fetch and compiles bcrypt locally in Heroku’s environment, avoiding permission issues.
3. Switch to bcryptjs (no compilation needed)
If you want to avoid native compilation entirely, use bcryptjs—it’s a pure JavaScript implementation of bcrypt with almost identical API:
- Uninstall bcrypt:
npm uninstall bcrypt - Install bcryptjs:
npm install bcryptjs - Update your code to replace
require('bcrypt')withrequire('bcryptjs')—all the core methods (likehash,compare) work the same way, so you won’t need major code changes.
Why did this work before but fail now?
Heroku regularly updates its Node.js buildpack and environment settings. It’s possible they tightened permissions or updated the Node.js version recently, which broke the old bcrypt@1.0.3’s node-pre-gyp workflow that worked before.
内容的提问来源于stack exchange,提问作者 coinhndp

