Bun Package Manager

作者 secondsky88378361314fMIT227 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫10 天前更新

Bun package manager commands (install, add, remove, update), workspaces, lockfiles, npm/yarn/pnpm migration. Use for dependency management with Bun.

AI 產生的概覽

Bun 套件管理員使用參考指南,涵蓋安裝、新增、移除、更新、鎖定檔、工作區,以及從 npm、yarn 和 pnpm 移轉。

功能
此技能提供使用 Bun 管理 JavaScript 相依性的說明與指令參考。它記錄了 bun install、bun add、bun remove、bun update 和 bunx 等核心指令,以及安裝旗標、鎖定檔處理、工作區與 monorepo 設定、生命週期指令碼信任設定、相依性覆寫、非 npm 相依性來源、安裝策略、CI/CD 用法、平台特定安裝、常見錯誤,以及從 npm、yarn 和 pnpm 移轉。它也指向其他參考檔案以取得完整 CLI 旗標、工作區和移轉資訊。
適用情境
適用於使用 Bun 作為套件管理員的情境:安裝或更新相依性、新增或移除套件、設定鎖定檔或工作區、建置 monorepo、從 npm、yarn 或 pnpm 移轉專案,或排解常見相依性錯誤。
執行需求
不包含指令碼,僅為說明文件。假定已安裝 Bun,且代理可以執行 Bun CLI 指令。安裝套件需要網路存取。它引用了其他檔案(references/cli-commands.md、references/workspaces.md、references/migration.md),但這些檔案未出現在提供的檔案清單中。

Bun Package Manager

Bun's package manager is a dramatically faster replacement for npm, yarn, and pnpm. Up to 25x faster than npm install.

Quick Start

bash
# Install all dependenciesbun install
# Add packagesbun add react react-dombun add -D typescript @types/react
# Remove packagesbun remove lodash
# Update packagesbun update
# Run package binariesbunx create-next-app

Core Commands

CommandDescription
bun installInstall all dependencies
bun add <pkg>Add dependency
bun add -D <pkg>Add dev dependency
bun add -O <pkg>Add optional dependency
bun add --peer <pkg>Add peer dependency
bun remove <pkg>Remove dependency
bun update [pkg]Update dependencies
bunx <pkg>Run package binary
bun pm cache rmClear cache

Installation Flags

bash
# Production mode (no devDependencies)bun install --production
# Frozen lockfile (CI/CD)bun install --frozen-lockfilebun ci  # shorthand
# Dry runbun install --dry-run
# Verbose/Silentbun install --verbosebun install --silent
# Force reinstallbun install --force
# Global packagesbun install -g cowsay

Lockfile

Bun uses bun.lock (text-based since v1.2):

bash
# Generate text lockfilebun install --save-text-lockfile
# Upgrade from binary bun.lockbbun install --save-text-lockfile --frozen-lockfile --lockfile-onlyrm bun.lockb

Workspaces (Monorepos)

json
{  "name": "my-monorepo",  "workspaces": ["packages/*", "apps/*"]}

Run commands across workspaces:

bash
# Run in matching packagesbun run --filter 'pkg-*' build
# Run in all workspacesbun run --filter '*' test
# Install for specific packagesbun install --filter 'pkg-a'

Lifecycle Scripts

Bun does not run lifecycle scripts from dependencies by default (security). Whitelist trusted packages:

json
{  "trustedDependencies": ["my-trusted-package"]}
bash
# Skip all lifecycle scriptsbun install --ignore-scripts
# Concurrent scriptsbun install --concurrent-scripts 5

Overrides & Resolutions

Force specific versions for nested dependencies:

json
{  "overrides": {    "lodash": "4.17.21"  }}

Yarn-style resolutions also supported:

json
{  "resolutions": {    "lodash": "4.17.21"  }}

Non-npm Dependencies

json
{  "dependencies": {    "dayjs": "git+https://github.com/iamkun/dayjs.git",    "lodash": "git+ssh://github.com/lodash/lodash.git#4.17.21",    "zod": "github:colinhacks/zod",    "react": "https://registry.npmjs.org/react/-/react-18.2.0.tgz",    "bun-types": "npm:@types/bun"  }}

Installation Strategies

Bun 1.3+ default flip: Starting in Bun 1.3, isolated is the default for workspaces (packages can no longer reach undeclared deps through the hoisted root node_modules). hoisted is now the legacy opt-out — only use it when a workspace package depends on a transitive dep that it doesn't declare.

Hoisted (legacy opt-out; still the default for single non-workspace packages)

Traditional flat node_modules:

bash
bun install --linker hoisted

Isolated (default for workspaces in Bun 1.3+)

pnpm-like strict isolation:

bash
bun install --linker isolated

Isolated prevents "phantom dependencies" - packages can only access declared dependencies. To make this explicit or restore it after an opt-out, set it in bunfig.toml:

toml
[install]linker = "isolated"   # default for workspaces in Bun 1.3+# linker = "hoisted"  # legacy opt-out

CI/CD

yaml
# GitHub Actions- uses: oven-sh/setup-bun@v2- run: bun ci  # frozen lockfile

Platform-Specific

bash
# Install for different platformbun install --cpu=x64 --os=linux

Secure Installation

When installing packages, follow supply chain security best practices:

  • Block post-install scripts — Bun disables them by default; allow specific packages via trustedDependencies in package.json
  • Cooldown period — Configure minimumReleaseAge in bunfig.toml to wait 7 days for new versions
  • Audit before installing — Run socket package score npm <pkg> or use socket npm install <pkg> to check packages before they reach your project

Load the dependency-upgrade skill for full security configuration including Socket CLI integration, cooldown setup, lockfile validation, and CI enforcement.

Common Errors

ErrorCauseFix
Cannot find moduleMissing dependencyRun bun install
Lockfile mismatchpackage.json changedRun bun install
Peer dependencyMissing peerbun add the peer
Lifecycle script failedUntrusted packageAdd to trustedDependencies

Migration from Other Package Managers

From pnpm

Bun automatically migrates pnpm-lock.yaml:

bash
bun install  # Auto-converts to bun.lock

Workspace config moves to package.json:

json
{  "workspaces": {    "packages": ["apps/*", "packages/*"],    "catalog": {      "react": "^18.0.0"    }  }}

From npm/Yarn

Simply run bun install - Bun reads package-lock.json and yarn.lock.

When to Load References

Load references/cli-commands.md when:

  • Need complete CLI flag reference
  • Working with advanced options

Load references/workspaces.md when:

  • Setting up monorepos
  • Configuring workspace filters

Load references/migration.md when:

  • Migrating from npm/yarn/pnpm
  • Converting lockfiles

來源與署名

來源:secondsky/claude-skills位於plugins/bun/skills/bun-package-manager提交8837836

授權條款: MIT

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架