Files
2026-08-27 21:09:14 +00:00

54 lines
2.1 KiB
Plaintext

---
title: Add a trusted dependency
sidebarTitle: Add a trusted dependency
mode: center
---
By default, Bun does not execute arbitrary lifecycle scripts for installed dependencies, such as `postinstall` and `node-gyp` builds. These scripts represent a potential security risk, as they can execute arbitrary code on your machine.
<Note>
Bun includes a default allowlist of popular packages whose `postinstall` scripts are known to be safe. See [the full
list](https://github.com/oven-sh/bun/blob/main/src/install/default-trusted-dependencies.txt). The allowlist only
applies to packages installed from npm. For packages from other sources (such as `file:`, `link:`, `git:`, or
`github:` dependencies), you must explicitly add them to `trustedDependencies`. Defining `trustedDependencies` in your
`package.json` [_replaces_ this default list](/pm/lifecycle#behavior-of-the-trusteddependencies-field) rather than
extending it, so also list any packages from the default list whose lifecycle scripts you still need.
</Note>
---
If you see one of the following errors, you are probably using a package that needs its `postinstall` script to work:
- `error: could not determine executable to run for package`
- `ENOEXEC` (`Exec format error`)
---
To allow Bun to execute lifecycle scripts for a specific package, add the package to `trustedDependencies` in your `package.json`. You can do this automatically by running `bun pm trust <pkg>`.
<Note>
Listing a package in `trustedDependencies` only allows lifecycle scripts for that specific package, _not_ the
dependencies of that dependency.
</Note>
```json package.json icon="file-json"
{
"name": "my-app",
"version": "1.0.0",
"trustedDependencies": ["my-trusted-package"] // [!code ++]
}
```
---
Once you add the package to `trustedDependencies`, run a fresh install. Bun re-installs your dependencies and runs the package's lifecycle scripts. (`bun pm trust` runs them immediately, so you can skip the extra install.)
```sh terminal icon="terminal"
rm -rf node_modules
bun install
```
---
See [trusted dependencies](/pm/lifecycle).