DRAFT: Add Bun Detector - #1860
Draft
zahidblackduck wants to merge 26 commits into
Draft
Conversation
zahidblackduck
marked this pull request as draft
August 21, 2026 15:41
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
JIRA Ticket
IDETECT-5295
Description
This pull request adds two new detectors for the Bun package manager support in Detect. Bun is an all-in-one JavaScript runtime, package manager, bundler, and test runner designed as a fast, drop-in replacement for Node.js and npm.
Bun Lockfile Detector (
HIGHaccuracy, buildless) parsesbun.lock. The JSONC-format lockfile introduced in Bun 1.2 (January 2025) as the standard for all current Bun projects. No executable is required.Bun CLI Detector (
LOWaccuracy, build) runsbun pm list --allas a best-effort fallback whenbun.lockis absent. It targets projects that have adopted Bun as their runtime but retain a lockfile from a previous npm, yarn, or pnpm setup. Bun auto-migrates these formats to produce the full dependency tree without requiringnode_modules/to be populated.The two detectors are registered under a single
BUNdetector type and yield toLERNAandRUSH, consistent with the existingnpmandyarndetectors.Requirements
Bun Lockfile Detector
bun.lockpresent (requires Bun 1.2+)Bun CLI Detector
bunexecutable onPATH(or specified viadetect.bun.path)package-lock.json,yarn.lock, orpnpm-lock.yamlpresentNew Detect Properties
detect.bun.path- Path to thebunexecutable. Optional; used only by the Bun CLI Detector whenbunis not onPATH.