Files
2026-08-27 21:09:14 +00:00

390 lines
9.7 KiB
Plaintext

---
title: "bun pm"
description: "Package manager utilities"
---
The `bun pm` command group is a set of utilities for working with Bun's package manager.
## pack
To create a tarball of the current workspace:
```bash terminal icon="terminal"
bun pm pack
```
`bun pm pack` creates a `.tgz` file containing all files that would be published to npm, following the same rules as `npm pack`.
## Examples
Basic usage:
```bash terminal icon="terminal"
bun pm pack
# Creates my-package-1.0.0.tgz in current directory
```
Quiet mode for scripting:
```bash terminal icon="terminal"
TARBALL=$(bun pm pack --quiet)
echo "Created: $TARBALL"
```
```txt
Created: my-package-1.0.0.tgz
```
Custom destination:
```bash terminal icon="terminal"
bun pm pack --destination ./dist
# Saves tarball in ./dist/ directory
```
## Options
- `--dry-run`: Perform all tasks except writing the tarball to disk. Shows what would be included.
- `--destination <dir>`: The directory to save the tarball in.
- `--filename <name>`: An exact file name for the tarball.
- `--ignore-scripts`: Skip running pre/postpack and prepare scripts.
- `--gzip-level <0-9>`: Set the gzip compression level, from 0 to 9 (default 9).
- `--quiet`: Print only the tarball filename, suppressing the rest of the output. Useful in scripts.
> **Note:** `--filename` and `--destination` cannot be used at the same time.
## Output Modes
**Default output:**
```bash terminal icon="terminal"
bun pm pack
```
```txt
bun pack v1.2.19
packed 131B package.json
packed 40B index.js
my-package-1.0.0.tgz
Total files: 2
Shasum: f2451d6eb1e818f500a791d9aace80b394258a90
Unpacked size: 171B
Packed size: 249B
```
**Quiet output:**
```bash terminal icon="terminal"
bun pm pack --quiet
```
```txt
my-package-1.0.0.tgz
```
## bin
To print the path to the `bin` directory for the local project:
```bash terminal icon="terminal"
bun pm bin
```
```txt
/path/to/current/project/node_modules/.bin
```
To print the path to the global `bin` directory:
```bash terminal icon="terminal"
bun pm bin -g
```
```txt
<$HOME>/.bun/bin
```
## ls
To print a list of installed dependencies in the current project and their resolved versions, excluding their dependencies:
```bash terminal icon="terminal"
bun pm ls
# or
bun list
```
```txt
/path/to/project node_modules (135)
├── [email protected]
├── [email protected]
├── [email protected]
├── [email protected]
└── [email protected]
```
To print all installed dependencies, including nth-order dependencies:
```bash terminal icon="terminal"
bun pm ls --all
# or
bun list --all
```
```txt
/path/to/project node_modules (135)
├── @eslint-community/[email protected]
├── @eslint-community/[email protected]
├── @eslint/[email protected]
├── @eslint/[email protected]
├── @nodelib/[email protected]
├── @nodelib/[email protected]
├── @nodelib/[email protected]
├── [email protected]
├── [email protected]
├── [email protected]
├── [email protected]
├── ...
```
To print only trusted dependencies (those allowed to run [lifecycle scripts](/pm/lifecycle)). When `trustedDependencies` is set in `package.json`, Bun shows the packages from that list; otherwise it shows packages from its [default trusted dependencies](https://github.com/oven-sh/bun/blob/main/src/install/default-trusted-dependencies.txt) list.
```bash terminal icon="terminal"
bun pm ls --trusted
# or
bun list --trusted
```
```txt
/path/to/project node_modules (135)
└── [email protected]
```
## licenses
List every installed package grouped by license, as read from each package's `package.json` in `node_modules`. Bun lists packages without a `license` field under `Unknown`. Bun marks packages only reachable through `devDependencies` with `(dev)`.
```bash terminal icon="terminal"
bun pm licenses
# or
bun pm licenses ls
```
```txt
MIT (2)
├── [email protected]
└── [email protected]
Unknown (4)
├── [email protected] (dev)
├── [email protected]
├── [email protected]
└── [email protected]
```
| Flag | Description |
| ------------------------------ | ------------------------------------------------------------------------------- |
| `--json` | Print a JSON object keyed by license |
| `--long` | Also print each package's `author`, `description`, and `homepage` |
| `--prod`, `-p` | Skip `devDependencies` (same as `--omit=dev`) |
| `--dev`, `-D` | Only list what `devDependencies` pull in |
| `--omit=<dev\|optional\|peer>` | Skip a dependency type, as with `bun install` |
| `--filter <pattern>`, `-F` | Only list dependencies of the matching workspaces ([filter syntax](/pm/filter)) |
```bash terminal icon="terminal"
bun pm licenses --json --prod
```
```json
{
"MIT": [
{
"name": "path-parse",
"versions": ["1.0.6"],
"paths": ["/home/me/app/node_modules/path-parse"],
"license": "MIT",
"homepage": "https://github.com/jbgutierrez/path-parse#readme",
"author": "Javier Blanco <http://jbgutierrez.info>",
"description": "Node.js path.parse() ponyfill"
}
]
}
```
From a workspace root, Bun lists every workspace's dependencies. From inside a workspace package, Bun lists only that package's dependencies. Use [`bun why`](/pm/cli/why) to find out what pulls in an unexpected package.
Requires both `bun.lock` and `node_modules`. Bun skips packages that are in the lockfile but missing from `node_modules` (e.g. after `bun install --production`) and prints a warning.
## whoami
Print your npm username. Requires you to be logged in (`bunx npm login`) with credentials in either `bunfig.toml` or `.npmrc`:
```bash terminal icon="terminal"
bun pm whoami
```
## hash
To generate and print the hash of the current lockfile:
```bash terminal icon="terminal"
bun pm hash
```
To print the string used to hash the lockfile:
```bash terminal icon="terminal"
bun pm hash-string
```
To print the hash stored in the current lockfile:
```bash terminal icon="terminal"
bun pm hash-print
```
## cache
To print the path to Bun's global module cache:
```bash terminal icon="terminal"
bun pm cache
```
To clear Bun's global module cache:
```bash terminal icon="terminal"
bun pm cache rm
```
## migrate
To migrate another package manager's lockfile without installing anything:
```bash terminal icon="terminal"
bun pm migrate
```
## untrusted
To print current untrusted dependencies with scripts:
```bash terminal icon="terminal"
bun pm untrusted
```
```txt
./node_modules/@biomejs/biome @1.8.3
» [postinstall]: node scripts/postinstall.js
These dependencies had their lifecycle scripts blocked during install.
```
## trust
To run scripts for untrusted dependencies and add to `trustedDependencies`:
```bash terminal icon="terminal"
bun pm trust <names>
```
Options for the `trust` command:
- `--all`: Trust all untrusted dependencies.
## default-trusted
To print the default trusted dependencies list:
```bash terminal icon="terminal"
bun pm default-trusted
```
See the [current list on GitHub](https://github.com/oven-sh/bun/blob/main/src/install/default-trusted-dependencies.txt).
## version
To display current package version and help:
```bash terminal icon="terminal"
bun pm version
```
```txt
bun pm version v1.3.3 (ca7428e9)
Current package version: v1.0.0
Increment:
patch 1.0.0 → 1.0.1
minor 1.0.0 → 1.1.0
major 1.0.0 → 2.0.0
prerelease 1.0.0 → 1.0.1-0
prepatch 1.0.0 → 1.0.1-0
preminor 1.0.0 → 1.1.0-0
premajor 1.0.0 → 2.0.0-0
from-git Use version from latest git tag
1.2.3 Set specific version
Options:
--no-git-tag-version Skip git operations
--allow-same-version Prevents throwing error if version is the same
--message=<val>, -m Custom commit message, use %s for version substitution
--preid=<val> Prerelease identifier (i.e beta → 1.0.1-beta.0)
--force, -f Bypass dirty git history check
Examples:
bun pm version patch
bun pm version 1.2.3 --no-git-tag-version
bun pm version prerelease --preid beta --message "Release beta: %s"
```
To bump the version in `package.json`:
```bash terminal icon="terminal"
bun pm version patch
```
```txt
v1.0.1
```
Supports `patch`, `minor`, `major`, `premajor`, `preminor`, `prepatch`, `prerelease`, `from-git`, or specific versions like `1.2.3`. By default it creates a git commit and tag; pass `--no-git-tag-version` to skip them.
## pkg
Manage `package.json` data with get, set, delete, and fix operations.
All commands support dot and bracket notation:
```bash terminal icon="terminal"
scripts.build # dot notation
contributors[0] # array access
workspaces.0 # dot with numeric index
scripts[test:watch] # bracket for special chars
```
Examples:
```bash terminal icon="terminal"
# get
bun pm pkg get name # single property
bun pm pkg get name version # multiple properties
bun pm pkg get # entire package.json
bun pm pkg get scripts.build # nested property
# set
bun pm pkg set name="my-package" # simple property
bun pm pkg set scripts.test="jest" version=2.0.0 # multiple properties
bun pm pkg set private=true --json # JSON values with --json flag
# delete
bun pm pkg delete description # single property
bun pm pkg delete scripts.test contributors[0] # multiple/nested
# fix
bun pm pkg fix # auto-fix common issues
```