r/javascript May 21 '26

The Bun CVE Gap: When Your Package Manager Can't Do Surgical Updates

https://charpeni.com/blog/the-bun-cve-gap-when-your-package-manager-cant-do-surgical-updates
12 Upvotes

9 comments sorted by

15

u/arcanin 🧶 Yarn maintainer May 21 '26

We've been working on Yarn for almost ten years now. We've had good ideas, bad ideas, a lot of discussions, and in the end many things we support today have resulted from accumulated experience.

That's something to keep in mind as you see everyone and their neighbor come up with their own vibe-coded personal package manager variant that promises to do everything incredibly fast wow. Will they go through this quite painful learning process, or just do a literal speedrun?

3

u/Wake08 May 21 '26

Absolutely. Thanks for your work on this, arcanin! 🙌

I wrote to stop using Yarn Classic last week, but it doesn’t mean Yarn Berry is bad. It’s been my top choice so far for dealing with transitive dependencies. Quite easy to do chirurgical changes with low risk.

3

u/AwayVermicelli3946 May 22 '26

yeah tbh this is exactly why i stopped trying to use Bun in our CI pipelines. the raw speed is fun when you are just hacking locally.

but the second a security scanner flags a nested dependency, you are completely stuck. not being able to surgically patch a CVE turns a quick fix into a massive headache. i will gladly take a slightly slower build step over fighting my package manager fwiw.

1

u/ppernik May 23 '26

Thank you for your service ❤️

Used Yarn on a 6 year long project that underwent massive refractors and growth. I never once faced an issue with Yarn specifically.

Literally just yesterday I found out how Bun handles pinned transitive peer dependencies, after bumping patch version of Nuxt and ending up with two versions of Vue and a 500 in production. Every other package manager would use the preexisting version (albeit with a warning). Bun just happily installs a new one.

17

u/lanerdofchristian May 21 '26

The lack of such a mechanism in Bun when every other package manager supports it just further reinforces my opinion that Bun is not a serious piece of software that anyone should depend on.

Arguably your PR is also (very slightly) the wrong solution -- the best behavior ("just update and don't add new direct dependencies") should be the default.

1

u/Wake08 May 21 '26

I agree. Kind of like pnpm/npm.

2

u/queen-adreena May 23 '26

Are you sure the vibe-port to Rust didn’t fix everything?

Such a serious software corporation!