Automic VaultAutomic Vault

brew

bun を Homebrew, chocolatey, MacPorts, Nix, pacman, scoop, winget でインストール

bun のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install bun

local Homebrew formula metadata

MacPorts確認済み · 94%
sudo port install bun

MacPorts ports tree · devel/bun/Portfile · ソース: api.github.com

概要

パッケージ概要

Incredibly fast JavaScript runtime, bundler, test runner, and package manager

コマンドとエイリアス

  • bun
  • bunx

履歴

プロジェクトの歴史と使われ方

Bun is an all-in-one JavaScript and TypeScript toolkit: runtime, package manager, script runner, test runner, package runner, and bundler shipped as a single executable.

プロジェクトの歴史

Bun was created as a response to the accumulated layers of Node.js-era JavaScript tooling. The official 1.0 announcement, published on September 8, 2023, framed Bun as a stable, production-ready toolkit for running, building, testing, and debugging JavaScript and TypeScript.

The project is powered by JavaScriptCore rather than V8 and is designed as a faster, leaner, more modern replacement for Node.js while preserving compatibility with npm packages, Node-style module resolution, CommonJS, ES modules, Web APIs, and many Node built-ins.

Bun's documentation later described it as written in Rust and powered by JavaScriptCore, while the GitHub README emphasizes that the single `bun` command includes the runtime plus test runner, script runner, package manager, and package runner.

採用の歴史

Bun moved from an alternative runtime curiosity into mainstream JavaScript tooling after the 1.0 release because it promised speed without forcing developers to abandon existing package.json projects. Official install paths include shell installer, npm, Homebrew, Docker, and Windows PowerShell, and package-manager metadata now lists it across Homebrew, Chocolatey, MacPorts, Nix, pacman, Scoop, and winget.

Its adoption is tied to projects experimenting with faster local feedback loops: replacing Node for script execution, replacing npm/yarn/pnpm for installs, replacing Jest/Vitest in some tests, and replacing separate bundlers for simple build cases.

使われ方

Common commands include `bun run` for scripts and TypeScript files, `bun install` for npm-compatible dependency installation, `bun test` for tests, `bun build` for bundling, and `bunx` for executing packages. Configuration is optional and lives in local or global `bunfig.toml` files for Bun-specific settings.

Bun's package manager writes `node_modules`, reads package.json, uses a global cache, and supports workspaces and npm registry configuration. Because it aims to run existing Node.js applications with little or no change, usage often starts as a drop-in replacement for selected scripts rather than a full-stack rewrite.

パッケージ好きにとっての重要性

Bun is significant because it collapses several previously separate JavaScript package tools into one binary. For package historians, it marks a major post-Node/npm phase where runtime, package manager, test runner, and bundler compete as integrated developer platforms rather than independent commands.

It is also important because it made package-manager performance and lockfile workflows part of a runtime's identity. Bun's rise pressured the broader ecosystem to treat install speed, TypeScript startup, test speed, and Node compatibility as one developer-experience surface.

タイムライン

  • 2023-09-08: Bun 1.0 announced as stable and production-ready.
  • 2024: 1.x releases continued expanding Node.js compatibility and toolkit coverage.
  • 2025: Official docs describe Bun as a runtime, package manager, test runner, and bundler for modern JavaScript and TypeScript apps.
  • 2026-05: GitHub release feed shows Bun v1.3.14 with ongoing 1.3.x releases.

Related projects

  • Bun is most directly related to Node.js, npm, yarn, pnpm, npx, ts-node, tsx, esbuild, webpack, Rollup, Parcel, Jest, Vitest, Deno, and the JavaScriptCore/WebKit project.

セキュリティ状態

保護ツール対応はまだ見つかっていません

bun に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、Nucleus パッケージメタデータはここに公開されています。

インストール挙動

  • Homebrew はこの formula に post-install フックを宣言しています。
  • Homebrew bottle メタデータは 6 個のプラットフォームターゲットで利用できます。
  • ビルドメタデータには 4 件のビルド依存関係があります。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
bunfig.toml~/.bunfig.toml$XDG_CONFIG_HOME/.bunfig.toml

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
bunfig.toml~/.bunfig.toml$XDG_CONFIG_HOME/.bunfig.toml

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
buncliグローバル実行可能ファイル
bunxcliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版1.3.14
マネージャ更新日2026-06-03
ローカルデータOK
上流not checked
検出された最新未検出

https://github.com/oven-sh/bun

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:bun
バージョン1.3.14
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/bun
ホームページhttps://bun.com/
リポジトリhttps://github.com/oven-sh/bun
上流ドキュメントhttps://bun.com/docs
ライセンスMIT AND LGPL-2.0-or-later AND Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND IJG AND LGPL-2.1-or-later AND Zlib AND (Apache-2.0 WITH LLVM-exception)
ソースアーカイブhttps://github.com/oven-sh/bun.git
最終更新2026-06-03T16:56:51Z
Pulseupdated
ビルド依存関係cmake, llvm@21, ninja, rust
Bottle利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install定義済み
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namebun
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Nix95%

bun

nix profile install nixpkgs#bun
  • normalized package name match
  • 一致条件: Bun
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/bu/bun/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
pacman95%

bun 1.3.14-1

Incredibly fast JavaScript runtime, bundler, test runner, and package manager – all in one

https://github.com/oven-sh/bun

sudo pacman -S bun
  • License: MIT
  • Architecture: x86_64
  • 2 依存関係
  • normalized package name match
  • 一致条件: Bun
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: bun from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

bun

sudo port install bun
  • normalized package name match
  • 一致条件: Bun
MacPorts ports tree · api.github.com · MacPorts ports tree: devel/bun/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Chocolatey95%

bun

choco install bun
  • normalized package name match
  • 一致条件: Bun
Chocolatey community package catalog · community.chocolatey.org · Chocolatey community package catalog: bun from http://community.chocolatey.org/api/v2/Packages?$filter=IsLatestVersion&$select=Id&$top=1000&$skiptoken='11','bluejeansapp'
Scoop95%

main/bun

scoop install main/bun
  • normalized package name match
  • 一致条件: Bun
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/bun.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1
winget95%

Oven-sh.Bun

winget install --id Oven-sh.Bun -e
  • normalized package name match
  • 一致条件: Bun
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: Oven-sh.Bun from https://cdn.winget.microsoft.com/cache/source.msix

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment