npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

danger-plugin-bun

v0.1.0

Published

Danger plugin reporting on dependency changes in Bun projects: registry details, bun why, bun.lock drift, and @types misplacement

Readme

danger-plugin-bun

A Danger plugin that reports on dependency changes in a pull request to a Bun project.

Inspired by danger-plugin-yarn by Orta Therox.

Usage

Install:

bun add --dev danger danger-plugin-bun

Add it to your Dangerfile:

// dangerfile.ts
import { schedule } from "danger";
import bun from "danger-plugin-bun";

schedule(bun());

bun() returns a Promise, so a Dangerfile can also await bun().

It runs four rules against every package.json the pull request creates or modifies:

  • checkForRelease: celebrates a version bump with a 🎉 message.
  • checkForNewDependencies: posts a table for each new dependency with its registry details (author, description, license, homepage, keywords, dates, release and maintainer counts, direct dependencies, and the README), followed by the output of bun why. A dependency added to several package.json files gets one table listing each of them.
  • checkForLockfileDiff: warns when dependencies, devDependencies, optionalDependencies, peerDependencies, or the workspace root's catalogs change but bun.lock does not.
  • checkForTypesInDeps: fails when an @types/* package is added to dependencies instead of devDependencies.

Options

bun({
	// Check one package.json; by default every created or modified package.json is checked.
	pathToPackageJSON: "packages/app/package.json",
	// A bearer token for private packages.
	npmAuthToken: process.env.NPM_TOKEN,
	// https://registry.npmjs.org when unset.
	npmRegistryUrl: "https://registry.example.com",

	disableCheckForRelease: false,
	disableCheckForNewDependencies: false,
	disableCheckForLockfileDiff: false,
	disableCheckForTypesInDeps: false,
});

Four rules are also exported on their own for Dangerfiles that compose their own checks: checkForRelease, checkForTypesInDeps, checkForLockfileDiff, and findNewDependencies.

Behavior

Which bun.lock is checked

bun install writes one bun.lock at the workspace root, so a change to a workspace member's package.json expects a change to the root lockfile. The plugin looks for the lockfile beside the nearest ancestor package.json that declares workspaces; outside any workspace, beside the nearest existing bun.lock; and otherwise at the repository root. A bun.lock the pull request creates counts as changed. Only the text lockfile is supported; bun.lockb is not.

Dependencies that skip the registry

Dependencies whose specifier does not resolve from the registry are left out of the new-dependency tables: workspace:, file:, link:, git and URL specifiers, and paths. An npm: alias is looked up under its target's name.

Catalogs

A catalog: or catalog:<name> dependency is resolved against the catalogs in the workspace root's package.json, where Bun reads them: under workspaces when that object holds catalog or catalogs, otherwise at the top level. catalog: and catalog:default read both catalog and catalogs.default. The catalog entry then follows the rules above: a registry range is looked up, an npm: alias is looked up under its target, and any other specifier is skipped. When the catalog or the entry is missing, the dependency's own name is looked up.

A change to the catalogs Bun reads counts as a dependency change for checkForLockfileDiff.

bun why

bun why --top <name> runs in the lockfile's directory, and its output appears under each table. When no bun binary is available the section is left out without a warning; when bun why fails the plugin warns.

New package.json files

Danger reports no diff for a file the pull request creates, so the plugin reads a created package.json from the checkout and treats every dependency in it as added.

Running Danger with Bun

Danger's command-line tool runs on Node through its shebang, so bunx danger ci works in a Bun project with a dangerfile.ts or a dangerfile.mjs.

The plugin ships CommonJS for require and an ES module entry for import, so it also loads when Danger's runner runs under Bun:

bunx danger ci -p "bun --bun node_modules/danger/distribution/commands/danger-runner.js"

Under the Bun runner, Danger evaluates a dangerfile.ts only when TypeScript and a tsconfig.json are installed in the project; a dangerfile.mjs needs neither.

Requirements: Node 26 or later, Bun 1.4 or later, and Danger 14 or later.

Development

bun install
bun run check   # build, type-check, test, lint, and check formatting
bun run fix     # apply lint autofixes and format

The repository's own pull requests run the plugin from ./dist through dangerfile.ts.

License

MIT. See LICENSE.md.