390 lines
9.7 KiB
Plaintext
390 lines
9.7 KiB
Plaintext
---
|
|
title: "bun pm"
|
|
description: "Package manager utilities"
|
|
---
|
|
|
|
The `bun pm` command group is a set of utilities for working with Bun's package manager.
|
|
|
|
## pack
|
|
|
|
To create a tarball of the current workspace:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm pack
|
|
```
|
|
|
|
`bun pm pack` creates a `.tgz` file containing all files that would be published to npm, following the same rules as `npm pack`.
|
|
|
|
## Examples
|
|
|
|
Basic usage:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm pack
|
|
# Creates my-package-1.0.0.tgz in current directory
|
|
```
|
|
|
|
Quiet mode for scripting:
|
|
|
|
```bash terminal icon="terminal"
|
|
TARBALL=$(bun pm pack --quiet)
|
|
echo "Created: $TARBALL"
|
|
```
|
|
|
|
```txt
|
|
Created: my-package-1.0.0.tgz
|
|
```
|
|
|
|
Custom destination:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm pack --destination ./dist
|
|
# Saves tarball in ./dist/ directory
|
|
```
|
|
|
|
## Options
|
|
|
|
- `--dry-run`: Perform all tasks except writing the tarball to disk. Shows what would be included.
|
|
- `--destination <dir>`: The directory to save the tarball in.
|
|
- `--filename <name>`: An exact file name for the tarball.
|
|
- `--ignore-scripts`: Skip running pre/postpack and prepare scripts.
|
|
- `--gzip-level <0-9>`: Set the gzip compression level, from 0 to 9 (default 9).
|
|
- `--quiet`: Print only the tarball filename, suppressing the rest of the output. Useful in scripts.
|
|
|
|
> **Note:** `--filename` and `--destination` cannot be used at the same time.
|
|
|
|
## Output Modes
|
|
|
|
**Default output:**
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm pack
|
|
```
|
|
|
|
```txt
|
|
bun pack v1.2.19
|
|
|
|
packed 131B package.json
|
|
packed 40B index.js
|
|
|
|
my-package-1.0.0.tgz
|
|
|
|
Total files: 2
|
|
Shasum: f2451d6eb1e818f500a791d9aace80b394258a90
|
|
Unpacked size: 171B
|
|
Packed size: 249B
|
|
```
|
|
|
|
**Quiet output:**
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm pack --quiet
|
|
```
|
|
|
|
```txt
|
|
my-package-1.0.0.tgz
|
|
```
|
|
|
|
## bin
|
|
|
|
To print the path to the `bin` directory for the local project:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm bin
|
|
```
|
|
|
|
```txt
|
|
/path/to/current/project/node_modules/.bin
|
|
```
|
|
|
|
To print the path to the global `bin` directory:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm bin -g
|
|
```
|
|
|
|
```txt
|
|
<$HOME>/.bun/bin
|
|
```
|
|
|
|
## ls
|
|
|
|
To print a list of installed dependencies in the current project and their resolved versions, excluding their dependencies:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm ls
|
|
# or
|
|
bun list
|
|
```
|
|
|
|
```txt
|
|
/path/to/project node_modules (135)
|
|
├── [email protected]
|
|
├── [email protected]
|
|
├── [email protected]
|
|
├── [email protected]
|
|
└── [email protected]
|
|
```
|
|
|
|
To print all installed dependencies, including nth-order dependencies:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm ls --all
|
|
# or
|
|
bun list --all
|
|
```
|
|
|
|
```txt
|
|
/path/to/project node_modules (135)
|
|
├── @eslint-community/[email protected]
|
|
├── @eslint-community/[email protected]
|
|
├── @eslint/[email protected]
|
|
├── @eslint/[email protected]
|
|
├── @nodelib/[email protected]
|
|
├── @nodelib/[email protected]
|
|
├── @nodelib/[email protected]
|
|
├── [email protected]
|
|
├── [email protected]
|
|
├── [email protected]
|
|
├── [email protected]
|
|
├── ...
|
|
```
|
|
|
|
To print only trusted dependencies (those allowed to run [lifecycle scripts](/pm/lifecycle)). When `trustedDependencies` is set in `package.json`, Bun shows the packages from that list; otherwise it shows packages from its [default trusted dependencies](https://github.com/oven-sh/bun/blob/main/src/install/default-trusted-dependencies.txt) list.
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm ls --trusted
|
|
# or
|
|
bun list --trusted
|
|
```
|
|
|
|
```txt
|
|
/path/to/project node_modules (135)
|
|
└── [email protected]
|
|
```
|
|
|
|
## licenses
|
|
|
|
List every installed package grouped by license, as read from each package's `package.json` in `node_modules`. Bun lists packages without a `license` field under `Unknown`. Bun marks packages only reachable through `devDependencies` with `(dev)`.
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm licenses
|
|
# or
|
|
bun pm licenses ls
|
|
```
|
|
|
|
```txt
|
|
MIT (2)
|
|
├── [email protected]
|
|
└── [email protected]
|
|
|
|
Unknown (4)
|
|
├── [email protected] (dev)
|
|
├── [email protected]
|
|
├── [email protected]
|
|
└── [email protected]
|
|
```
|
|
|
|
| Flag | Description |
|
|
| ------------------------------ | ------------------------------------------------------------------------------- |
|
|
| `--json` | Print a JSON object keyed by license |
|
|
| `--long` | Also print each package's `author`, `description`, and `homepage` |
|
|
| `--prod`, `-p` | Skip `devDependencies` (same as `--omit=dev`) |
|
|
| `--dev`, `-D` | Only list what `devDependencies` pull in |
|
|
| `--omit=<dev\|optional\|peer>` | Skip a dependency type, as with `bun install` |
|
|
| `--filter <pattern>`, `-F` | Only list dependencies of the matching workspaces ([filter syntax](/pm/filter)) |
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm licenses --json --prod
|
|
```
|
|
|
|
```json
|
|
{
|
|
"MIT": [
|
|
{
|
|
"name": "path-parse",
|
|
"versions": ["1.0.6"],
|
|
"paths": ["/home/me/app/node_modules/path-parse"],
|
|
"license": "MIT",
|
|
"homepage": "https://github.com/jbgutierrez/path-parse#readme",
|
|
"author": "Javier Blanco <http://jbgutierrez.info>",
|
|
"description": "Node.js path.parse() ponyfill"
|
|
}
|
|
]
|
|
}
|
|
```
|
|
|
|
From a workspace root, Bun lists every workspace's dependencies. From inside a workspace package, Bun lists only that package's dependencies. Use [`bun why`](/pm/cli/why) to find out what pulls in an unexpected package.
|
|
|
|
Requires both `bun.lock` and `node_modules`. Bun skips packages that are in the lockfile but missing from `node_modules` (e.g. after `bun install --production`) and prints a warning.
|
|
|
|
## whoami
|
|
|
|
Print your npm username. Requires you to be logged in (`bunx npm login`) with credentials in either `bunfig.toml` or `.npmrc`:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm whoami
|
|
```
|
|
|
|
## hash
|
|
|
|
To generate and print the hash of the current lockfile:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm hash
|
|
```
|
|
|
|
To print the string used to hash the lockfile:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm hash-string
|
|
```
|
|
|
|
To print the hash stored in the current lockfile:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm hash-print
|
|
```
|
|
|
|
## cache
|
|
|
|
To print the path to Bun's global module cache:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm cache
|
|
```
|
|
|
|
To clear Bun's global module cache:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm cache rm
|
|
```
|
|
|
|
## migrate
|
|
|
|
To migrate another package manager's lockfile without installing anything:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm migrate
|
|
```
|
|
|
|
## untrusted
|
|
|
|
To print current untrusted dependencies with scripts:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm untrusted
|
|
```
|
|
|
|
```txt
|
|
./node_modules/@biomejs/biome @1.8.3
|
|
» [postinstall]: node scripts/postinstall.js
|
|
|
|
These dependencies had their lifecycle scripts blocked during install.
|
|
```
|
|
|
|
## trust
|
|
|
|
To run scripts for untrusted dependencies and add to `trustedDependencies`:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm trust <names>
|
|
```
|
|
|
|
Options for the `trust` command:
|
|
|
|
- `--all`: Trust all untrusted dependencies.
|
|
|
|
## default-trusted
|
|
|
|
To print the default trusted dependencies list:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm default-trusted
|
|
```
|
|
|
|
See the [current list on GitHub](https://github.com/oven-sh/bun/blob/main/src/install/default-trusted-dependencies.txt).
|
|
|
|
## version
|
|
|
|
To display current package version and help:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm version
|
|
```
|
|
|
|
```txt
|
|
bun pm version v1.3.3 (ca7428e9)
|
|
Current package version: v1.0.0
|
|
|
|
Increment:
|
|
patch 1.0.0 → 1.0.1
|
|
minor 1.0.0 → 1.1.0
|
|
major 1.0.0 → 2.0.0
|
|
prerelease 1.0.0 → 1.0.1-0
|
|
prepatch 1.0.0 → 1.0.1-0
|
|
preminor 1.0.0 → 1.1.0-0
|
|
premajor 1.0.0 → 2.0.0-0
|
|
from-git Use version from latest git tag
|
|
1.2.3 Set specific version
|
|
|
|
Options:
|
|
--no-git-tag-version Skip git operations
|
|
--allow-same-version Prevents throwing error if version is the same
|
|
--message=<val>, -m Custom commit message, use %s for version substitution
|
|
--preid=<val> Prerelease identifier (i.e beta → 1.0.1-beta.0)
|
|
--force, -f Bypass dirty git history check
|
|
|
|
Examples:
|
|
bun pm version patch
|
|
bun pm version 1.2.3 --no-git-tag-version
|
|
bun pm version prerelease --preid beta --message "Release beta: %s"
|
|
```
|
|
|
|
To bump the version in `package.json`:
|
|
|
|
```bash terminal icon="terminal"
|
|
bun pm version patch
|
|
```
|
|
|
|
```txt
|
|
v1.0.1
|
|
```
|
|
|
|
Supports `patch`, `minor`, `major`, `premajor`, `preminor`, `prepatch`, `prerelease`, `from-git`, or specific versions like `1.2.3`. By default it creates a git commit and tag; pass `--no-git-tag-version` to skip them.
|
|
|
|
## pkg
|
|
|
|
Manage `package.json` data with get, set, delete, and fix operations.
|
|
|
|
All commands support dot and bracket notation:
|
|
|
|
```bash terminal icon="terminal"
|
|
scripts.build # dot notation
|
|
contributors[0] # array access
|
|
workspaces.0 # dot with numeric index
|
|
scripts[test:watch] # bracket for special chars
|
|
```
|
|
|
|
Examples:
|
|
|
|
```bash terminal icon="terminal"
|
|
# get
|
|
bun pm pkg get name # single property
|
|
bun pm pkg get name version # multiple properties
|
|
bun pm pkg get # entire package.json
|
|
bun pm pkg get scripts.build # nested property
|
|
|
|
# set
|
|
bun pm pkg set name="my-package" # simple property
|
|
bun pm pkg set scripts.test="jest" version=2.0.0 # multiple properties
|
|
bun pm pkg set private=true --json # JSON values with --json flag
|
|
|
|
# delete
|
|
bun pm pkg delete description # single property
|
|
bun pm pkg delete scripts.test contributors[0] # multiple/nested
|
|
|
|
# fix
|
|
bun pm pkg fix # auto-fix common issues
|
|
```
|