Files
2026-08-27 21:09:14 +00:00

122 lines
5.3 KiB
Plaintext

---
title: "bun audit"
description: "Check your installed packages for known security vulnerabilities"
---
Run the command in a project with a `bun.lock` file:
```bash terminal icon="terminal"
bun audit
```
Bun reads the package list from `bun.lock` (no `node_modules` required), sends it to the npm advisory endpoint, and prints a report. Bun sends packages from a scoped registry to that registry instead. If that registry has no advisory endpoint, Bun lists those packages as skipped and they don't affect the exit code.
`bun audit` never modifies `package.json`, `bun.lock`, or `node_modules`. To apply fixes, use [`bun audit fix`](#bun-audit-fix).
If Bun finds no vulnerabilities, the command prints:
```
No vulnerabilities found
```
Otherwise, Bun lists each affected package with its severity, a short description, and a link to the advisory, followed by a summary:
```
3 vulnerabilities (1 high, 2 moderate)
bun audit fix upgrade the vulnerable packages within their ranges
bun audit fix --latest also cross major versions
```
### Filtering options
**`--audit-level=<low|moderate|high|critical>`** - Only report vulnerabilities at this severity or higher:
```bash terminal icon="terminal"
bun audit --audit-level=high
```
**`--prod`** (`-p`, `-P`, `--production`) - Only audit packages reachable through `dependencies`, `optionalDependencies`, or `peerDependencies`:
```bash terminal icon="terminal"
bun audit --prod
```
**`--omit=<dev|optional|peer>`** - Skip packages only reachable through the given dependency type. Repeatable. `--omit=dev` is the same as `--prod`:
```bash terminal icon="terminal"
bun audit --omit=optional --omit=peer
```
**`--ignore <id>`** - Ignore an advisory by GHSA ID or numeric ID. Repeatable. (CVE IDs are not in the registry data and don't match.)
```bash terminal icon="terminal"
bun audit --ignore GHSA-c2qf-rxjj-qqgw --ignore 1112918
```
These options are CLI-only; to apply them on every run, put them in a `package.json` script.
### `--json`
Print the raw JSON response from the registry instead of the formatted report:
```bash terminal icon="terminal"
bun audit --json
```
The JSON is unfiltered — `--audit-level` and `--ignore` only affect the exit code.
### `bun audit fix`
```bash terminal icon="terminal"
bun audit fix
```
Runs the audit, then upgrades each vulnerable package to the lowest non-vulnerable version that every dependent's range allows, and installs. Only `bun.lock` and `node_modules` change, with one exception: Bun treats a direct dependency pinned to an exact version as `^version`. If Bun finds a fix, it rewrites the pin in `package.json` (or the catalog entry).
```
fixing:
[email protected] → 0.7.1
[email protected] → 4.17.21
package.json: 4.17.20 → 4.17.21
blocked by a dependent's range:
[email protected] → 3.0.2
[email protected] depends on [email protected]
[email protected] → 6.3.1
my-app depends on semver@^5.0.0
bun audit fix --latest
no published version fixes:
[email protected] GHSA-xxxx-xxxx-xxxx
bun audit fix --ignore GHSA-xxxx-xxxx-xxxx
Fixed 2 vulnerabilities in 2 packages
5 vulnerabilities remaining
```
- **blocked by a dependent's range** — no safe version fits a dependent's declared range. If the range is in your own `package.json` or catalog, `bun audit fix --latest` gets past it. Otherwise, update the dependent or add an [`overrides`](/pm/overrides) entry.
- **no published version fixes** — every published version is vulnerable. Replace the package, or silence the advisory with the printed `--ignore` command.
- If no newer version is safe but an older one is, Bun downgrades and marks the row `(downgrade)`.
- Bun still installs a safe version newer than `--minimum-release-age` and marks the row `(newer than --minimum-release-age)`.
- Bun upgrades patched dependencies (`patchedDependencies`) like any other package. Re-create the patch afterwards with `bun patch`.
- After installing, Bun re-audits the new lockfile. The `remaining` count and exit code reflect that second audit, so they match what a follow-up `bun audit` would report.
- `--dry-run` prints the plan without installing.
- `--json` prints a single JSON object describing the plan and result (`fixes`, `blocked`, `unfixable`, `unmatched`, `unaudited`, `vulnerableAfterInstall`, `fixed`, `remaining`, `dryRun`). Pass `--ignore-scripts` if lifecycle scripts might write to stdout.
- A [security scanner](/pm/security-scanner-api) configured in `bunfig.toml` runs on the packages about to be installed, as with `bun update`.
- Bun rejects `--prod`, `--frozen-lockfile`, and `--no-save` since they prevent writing `bun.lock`.
### `bun audit fix --latest`
```bash terminal icon="terminal"
bun audit fix --latest
```
Same as `bun audit fix`, but ranges in your own `package.json` files and catalogs no longer block a fix. Bun rewrites them to accept the new version, keeping their style (`^5.0.0` → `^6.3.1`, `~5.7.1` → `~6.3.1`, exact stays exact). Ranges declared by third-party packages still block; use `overrides` for those.
### Exit code
`0` if no vulnerabilities remain after Bun applies `--audit-level` and `--ignore`, `1` otherwise. For `bun audit fix`, this is based on the re-audit after installing (or the plan, with `--dry-run`).
If the registry request fails, both commands print `audit request failed` to stderr and exit `1`.