danger-plugin-bun
v0.1.0
Published
Danger plugin reporting on dependency changes in Bun projects: registry details, bun why, bun.lock drift, and @types misplacement
Readme
danger-plugin-bun
A Danger plugin that reports on dependency changes in a pull request to a Bun project.
Inspired by danger-plugin-yarn by Orta Therox.
Usage
Install:
bun add --dev danger danger-plugin-bunAdd it to your Dangerfile:
// dangerfile.ts
import { schedule } from "danger";
import bun from "danger-plugin-bun";
schedule(bun());bun() returns a Promise, so a Dangerfile can also await bun().
It runs four rules against every package.json the pull request creates or modifies:
checkForRelease: celebrates aversionbump with a 🎉 message.checkForNewDependencies: posts a table for each new dependency with its registry details (author, description, license, homepage, keywords, dates, release and maintainer counts, direct dependencies, and the README), followed by the output ofbun why. A dependency added to severalpackage.jsonfiles gets one table listing each of them.checkForLockfileDiff: warns whendependencies,devDependencies,optionalDependencies,peerDependencies, or the workspace root's catalogs change butbun.lockdoes not.checkForTypesInDeps: fails when an@types/*package is added todependenciesinstead ofdevDependencies.
Options
bun({
// Check one package.json; by default every created or modified package.json is checked.
pathToPackageJSON: "packages/app/package.json",
// A bearer token for private packages.
npmAuthToken: process.env.NPM_TOKEN,
// https://registry.npmjs.org when unset.
npmRegistryUrl: "https://registry.example.com",
disableCheckForRelease: false,
disableCheckForNewDependencies: false,
disableCheckForLockfileDiff: false,
disableCheckForTypesInDeps: false,
});Four rules are also exported on their own for Dangerfiles that compose their own checks: checkForRelease, checkForTypesInDeps, checkForLockfileDiff, and findNewDependencies.
Behavior
Which bun.lock is checked
bun install writes one bun.lock at the workspace root, so a change to a workspace member's package.json expects a change to the root lockfile. The plugin looks for the lockfile beside the nearest ancestor package.json that declares workspaces; outside any workspace, beside the nearest existing bun.lock; and otherwise at the repository root. A bun.lock the pull request creates counts as changed. Only the text lockfile is supported; bun.lockb is not.
Dependencies that skip the registry
Dependencies whose specifier does not resolve from the registry are left out of the new-dependency tables: workspace:, file:, link:, git and URL specifiers, and paths. An npm: alias is looked up under its target's name.
Catalogs
A catalog: or catalog:<name> dependency is resolved against the catalogs in the workspace root's package.json, where Bun reads them: under workspaces when that object holds catalog or catalogs, otherwise at the top level. catalog: and catalog:default read both catalog and catalogs.default. The catalog entry then follows the rules above: a registry range is looked up, an npm: alias is looked up under its target, and any other specifier is skipped. When the catalog or the entry is missing, the dependency's own name is looked up.
A change to the catalogs Bun reads counts as a dependency change for checkForLockfileDiff.
bun why
bun why --top <name> runs in the lockfile's directory, and its output appears under each table. When no bun binary is available the section is left out without a warning; when bun why fails the plugin warns.
New package.json files
Danger reports no diff for a file the pull request creates, so the plugin reads a created package.json from the checkout and treats every dependency in it as added.
Running Danger with Bun
Danger's command-line tool runs on Node through its shebang, so bunx danger ci works in a Bun project with a dangerfile.ts or a dangerfile.mjs.
The plugin ships CommonJS for require and an ES module entry for import, so it also loads when Danger's runner runs under Bun:
bunx danger ci -p "bun --bun node_modules/danger/distribution/commands/danger-runner.js"Under the Bun runner, Danger evaluates a dangerfile.ts only when TypeScript and a tsconfig.json are installed in the project; a dangerfile.mjs needs neither.
Requirements: Node 26 or later, Bun 1.4 or later, and Danger 14 or later.
Development
bun install
bun run check # build, type-check, test, lint, and check formatting
bun run fix # apply lint autofixes and formatThe repository's own pull requests run the plugin from ./dist through dangerfile.ts.
License
MIT. See LICENSE.md.
