Bun Package Manager
Bun's package manager is a dramatically faster replacement for npm, yarn, and pnpm. Up to 25x faster than npm install.
Quick Start
Core Commands
Installation Flags
Lockfile
Bun uses bun.lock (text-based since v1.2):
Workspaces (Monorepos)
Run commands across workspaces:
Lifecycle Scripts
Bun does not run lifecycle scripts from dependencies by default (security). Whitelist trusted packages:
Overrides & Resolutions
Force specific versions for nested dependencies:
Yarn-style resolutions also supported:
Non-npm Dependencies
Installation Strategies
Bun 1.3+ default flip: Starting in Bun 1.3,
isolatedis the default for workspaces (packages can no longer reach undeclared deps through the hoisted rootnode_modules).hoistedis now the legacy opt-out — only use it when a workspace package depends on a transitive dep that it doesn't declare.
Hoisted (legacy opt-out; still the default for single non-workspace packages)
Traditional flat node_modules:
Isolated (default for workspaces in Bun 1.3+)
pnpm-like strict isolation:
Isolated prevents "phantom dependencies" - packages can only access declared dependencies. To make this explicit or restore it after an opt-out, set it in bunfig.toml:
CI/CD
Platform-Specific
Secure Installation
When installing packages, follow supply chain security best practices:
- Block post-install scripts — Bun disables them by default; allow specific packages via
trustedDependenciesinpackage.json - Cooldown period — Configure
minimumReleaseAgeinbunfig.tomlto wait 7 days for new versions - Audit before installing — Run
socket package score npm <pkg>or usesocket npm install <pkg>to check packages before they reach your project
Load the dependency-upgrade skill for full security configuration including Socket CLI integration, cooldown setup, lockfile validation, and CI enforcement.
Common Errors
Migration from Other Package Managers
From pnpm
Bun automatically migrates pnpm-lock.yaml:
Workspace config moves to package.json:
From npm/Yarn
Simply run bun install - Bun reads package-lock.json and yarn.lock.
When to Load References
Load references/cli-commands.md when:
- Need complete CLI flag reference
- Working with advanced options
Load references/workspaces.md when:
- Setting up monorepos
- Configuring workspace filters
Load references/migration.md when:
- Migrating from npm/yarn/pnpm
- Converting lockfiles


