bun
2
Versions
—
License
Yes
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
jarredrobobun
Keywords
bunbun.jsnodenode.jsruntimebundlertranspilertypescript
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:postinstall | AI (install-scripts): Bun's postinstall runs install.js to link platform-specific prebuilt binaries from @oven/bun-* optional deps. This is the documented, stable install pattern for this package. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): 'bun' is the official Bun runtime package by oven-sh with 1297 versions and years of history. Levenshtein match to 'yup' is a false positive; no typosquat relationship exists. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process is used in install.js to set up platform-specific binaries. This is expected for a binary runtime installer and is publicly auditable at oven-sh/bun on GitHub. | ai |
v1.2.5
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.