{"_id":"bun-scan","_rev":"9-77ac2f862df4567ef1cf567d36b5bd71","name":"bun-scan","dist-tags":{"latest":"1.1.2","beta":"1.1.1-beta.2"},"versions":{"1.0.1":{"name":"bun-scan","version":"1.0.1","keywords":["audit","bun","dependencies","osv","scanner","security","security-scanner","vulnerability","vulnerability-scanner"],"author":{"name":"rawtoast"},"license":"MIT","_id":"bun-scan@1.0.1","maintainers":[{"name":"namatoast","email":"jmorris@itazuramono.com"}],"homepage":"https://github.com/RawToast/bun-scan","bugs":{"url":"https://github.com/RawToast/bun-scan/issues"},"dist":{"shasum":"b05532fe52e8244aa29f69216723a192837faed2","tarball":"https://registry.npmjs.org/bun-scan/-/bun-scan-1.0.1.tgz","fileCount":16,"integrity":"sha512-6frEs//PHKsiXqV8Q3nAyCCVZ8EVi7s4EkSjVI+CVjCp90CQJ00q0W3ugehU/9tscRQQfaC741OWFG935FwbhQ==","signatures":[{"sig":"MEQCIHF2IF9US0WqE0I9kIIh1ur3niAn8bm/xdu5e80LA8EcAiBaEkHZMl4IZGwv8Qd3fNTTdpnNElS1LbaOJt2msZfn/Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/bun-scan@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":66705},"type":"module","types":"./src/index.ts","engines":{"bun":">=1.0.0"},"exports":"./src/index.ts","funding":{"url":"https://github.com/sponsors/RawToast","type":"github"},"gitHead":"0d795aa46d1139e4b8c57d51c83f1e0cf58b54bd","scripts":{"dev":"tsgo --watch --noEmit","lint":"oxlint","build":"bun run check","check":"bun format && bun lint:check && bun compile && bun test","clean":"rm -rf dist build node_modules/.cache","format":"oxfmt","compile":"tsgo --noEmit","prepare":"bunx lefthook install","lint:check":"oxlint check","format:check":"oxfmt --check"},"_npmUser":{"name":"namatoast","email":"jmorris@itazuramono.com"},"repository":{"url":"git+https://github.com/RawToast/bun-scan.git","type":"git"},"_npmVersion":"10.8.2","description":"OSV vulnerability scanner for Bun projects","directories":{},"_nodeVersion":"20.19.6","dependencies":{"zod":"4.3.5"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.0","devDependencies":{"oxfmt":"0.24.0","oxlint":"1.39.0","lefthook":"2.0.15","@types/bun":"1.3.6","@tsconfig/bun":"1.0.10","@typescript/native-preview":"7.0.0-dev.20260114.1"},"_npmOperationalInternal":{"tmp":"tmp/bun-scan_1.0.1_1768449798121_0.42333295508124014","host":"s3://npm-registry-packages-npm-production"}},"1.1.0-beta.1":{"name":"bun-scan","version":"1.1.0-beta.1","keywords":["audit","bun","dependencies","osv","scanner","security","security-scanner","vulnerability","vulnerability-scanner"],"author":{"name":"rawtoast"},"license":"MIT","_id":"bun-scan@1.1.0-beta.1","maintainers":[{"name":"namatoast","email":"jmorris@itazuramono.com"}],"homepage":"https://github.com/RawToast/bun-scan","bugs":{"url":"https://github.com/RawToast/bun-scan/issues"},"dist":{"shasum":"12a396ebba67a0b41fff15ac27e3a64552f78327","tarball":"https://registry.npmjs.org/bun-scan/-/bun-scan-1.1.0-beta.1.tgz","fileCount":43,"integrity":"sha512-WzJ1njIcMFHWr8JLF8HSyrcteMMhPW6DTKR2hL0zK6Xw7rCzDfUhad2mNxRd0Rbu4/6Fr67/oJTo0BBB6leoNw==","signatures":[{"sig":"MEUCIQDlc2/0Nc4qhupKsi1mlrQ8vT5JqWbEytLm4awFA0m9sgIgLTjOndIAUgnJKrCzIxxIq9U3pVz7TBBswz9TljaBZ2U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/bun-scan@1.1.0-beta.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":250687},"type":"module","types":"./src/index.ts","engines":{"bun":">=1.0.0"},"exports":"./src/index.ts","funding":{"url":"https://github.com/sponsors/RawToast","type":"github"},"gitHead":"1b36365e61558f2f2d4378bbcc78e655a1eae8d0","scripts":{"dev":"tsgo --watch --noEmit","lint":"oxlint","build":"bun run check","check":"bun format && bun lint:check && bun compile && bun test","clean":"rm -rf dist build node_modules/.cache","format":"oxfmt","compile":"tsgo --noEmit","prepare":"bunx lefthook install","lint:check":"oxlint check","format:check":"oxfmt --check"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1e721df6-bd07-438b-9f62-02eb33d51b70"}},"repository":{"url":"git+https://github.com/RawToast/bun-scan.git","type":"git"},"_npmVersion":"11.6.2","description":"Vulnerability scanner for Bun projects","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"4.3.5"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.0","readmeFilename":"README.md","devDependencies":{"oxfmt":"0.24.0","oxlint":"1.39.0","lefthook":"2.0.15","@types/bun":"1.3.6","@typescript/native-preview":"7.0.0-dev.20260114.1"},"_npmOperationalInternal":{"tmp":"tmp/bun-scan_1.1.0-beta.1_1768636130414_0.7559658907714804","host":"s3://npm-registry-packages-npm-production"}},"1.1.0-beta.2":{"name":"bun-scan","version":"1.1.0-beta.2","keywords":["audit","bun","dependencies","osv","scanner","security","security-scanner","vulnerability","vulnerability-scanner"],"author":{"name":"rawtoast"},"license":"MIT","_id":"bun-scan@1.1.0-beta.2","maintainers":[{"name":"namatoast","email":"jmorris@itazuramono.com"}],"homepage":"https://github.com/RawToast/bun-scan","bugs":{"url":"https://github.com/RawToast/bun-scan/issues"},"bin":{"bun-scan":"dist/cli.js"},"dist":{"shasum":"76893abe59ada06697ceea1a7066dde0bc94402b","tarball":"https://registry.npmjs.org/bun-scan/-/bun-scan-1.1.0-beta.2.tgz","fileCount":11,"integrity":"sha512-rPTnc5DV996GJ5htSWdBZYEcjEnUURGKUAeXk8YH3La0U/sRBSBICKTo+nlZBxsqYljPUkOVwwOqIYideqO7/g==","signatures":[{"sig":"MEQCIG0yytBmYhSpjve2ttWJZ7GRVyylErsOJ5drX4UvwLMeAiA9XFAzyh0KoP40IG0Tp1xlJsoNhyQAapdPga/FAgMrWA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/bun-scan@1.1.0-beta.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":120517},"type":"module","types":"./src/index.ts","engines":{"bun":">=1.0.0"},"exports":{".":{"types":"./src/index.ts","default":"./dist/index.js"}},"funding":{"url":"https://github.com/sponsors/RawToast","type":"github"},"gitHead":"8981d4b2bb64f333afecc7092ad698e79dc688fd","scripts":{"lint":"oxlint check","test":"bun test","build":"bun build src/index.ts --outdir dist --target bun --external zod && bun build src/cli.ts --outdir dist --target bun --external zod","compile":"tsgo --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1e721df6-bd07-438b-9f62-02eb33d51b70"}},"repository":{"url":"git+https://github.com/RawToast/bun-scan.git","type":"git"},"_npmVersion":"11.6.2","description":"Vulnerability scanner for Bun projects","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"4.3.5","@repo/core":"workspace:*","@repo/source-npm":"workspace:*","@repo/source-osv":"workspace:*"},"_hasShrinkwrap":false,"devDependencies":{"bun-types":"1.3.6","@types/bun":"1.3.6","@typescript/native-preview":"7.0.0-dev.20260114.1"},"_npmOperationalInternal":{"tmp":"tmp/bun-scan_1.1.0-beta.2_1768708841767_0.4738836136035147","host":"s3://npm-registry-packages-npm-production"}},"1.1.0-beta.3":{"name":"bun-scan","version":"1.1.0-beta.3","keywords":["audit","bun","dependencies","osv","scanner","security","security-scanner","vulnerability","vulnerability-scanner"],"author":{"name":"rawtoast"},"license":"MIT","_id":"bun-scan@1.1.0-beta.3","maintainers":[{"name":"namatoast","email":"jmorris@itazuramono.com"}],"homepage":"https://github.com/RawToast/bun-scan","bugs":{"url":"https://github.com/RawToast/bun-scan/issues"},"bin":{"bun-scan":"dist/cli.js"},"dist":{"shasum":"741c90796e96fde3a8fcffe6d424373b91c3f313","tarball":"https://registry.npmjs.org/bun-scan/-/bun-scan-1.1.0-beta.3.tgz","fileCount":4,"integrity":"sha512-y2j4AjEB8tM9FnEECk3blrWMV1NsrKIyVeBgHWPNaoRD2ykw2jX2YMzVcYUAwmt2k1aVwiW6+h07wuS4f8DMOQ==","signatures":[{"sig":"MEQCIHkLXh1n/nrjk3UHxY8HNggRIDzXFi/UmadSUzcm3N0xAiAfqoWmMWbpA978qgghNE94YZ0Y3y45T0yF0YYnVwtBEw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/bun-scan@1.1.0-beta.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":100960},"type":"module","types":"./dist/index.d.ts","engines":{"bun":">=1.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"funding":{"url":"https://github.com/sponsors/RawToast","type":"github"},"gitHead":"9eb316f8bfa4ad6b1a3cc2e1393a4e97845c3cfa","scripts":{"lint":"oxlint check","test":"bun test","build":"bun build src/index.ts --outdir dist --target bun --external zod && bun build src/cli.ts --outdir dist --target bun --external zod && cp types/index.d.ts dist/","compile":"tsgo --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1e721df6-bd07-438b-9f62-02eb33d51b70"}},"repository":{"url":"git+https://github.com/RawToast/bun-scan.git","type":"git"},"_npmVersion":"11.6.2","description":"Vulnerability scanner for Bun projects","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"4.3.5"},"_hasShrinkwrap":false,"devDependencies":{"bun-types":"1.3.6","@repo/core":"workspace:*","@types/bun":"1.3.6","@repo/source-npm":"workspace:*","@repo/source-osv":"workspace:*","@typescript/native-preview":"7.0.0-dev.20260114.1"},"_npmOperationalInternal":{"tmp":"tmp/bun-scan_1.1.0-beta.3_1768709474671_0.9201345828933747","host":"s3://npm-registry-packages-npm-production"}},"1.1.0-beta.4":{"name":"bun-scan","version":"1.1.0-beta.4","keywords":["audit","bun","dependencies","osv","scanner","security","security-scanner","vulnerability","vulnerability-scanner"],"author":{"name":"rawtoast"},"license":"MIT","_id":"bun-scan@1.1.0-beta.4","maintainers":[{"name":"namatoast","email":"jmorris@itazuramono.com"}],"homepage":"https://github.com/RawToast/bun-scan","bugs":{"url":"https://github.com/RawToast/bun-scan/issues"},"bin":{"bun-scan":"dist/cli.js"},"dist":{"shasum":"15c44a97e900b0290eafe44e26cc3158770a2844","tarball":"https://registry.npmjs.org/bun-scan/-/bun-scan-1.1.0-beta.4.tgz","fileCount":4,"integrity":"sha512-CrXPvyYzgvAMgwbOWEndYN3Mk+/6hCcO9FpVFm7ZL/CxdmOEecURkWeOpSKOWJoxRrfVRNCMb+5DioWa/1s1vg==","signatures":[{"sig":"MEUCIQDZpZ15qfkK14/MFc3lN7kA53npVxTPDDnoy77OFPqx3QIgLSorbiWS0Uj+KUDPWIO6Kjy0xZt1Rpr9UOg11Q4Yq2o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/bun-scan@1.1.0-beta.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":110513},"type":"module","types":"./dist/index.d.ts","engines":{"bun":">=1.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"funding":{"url":"https://github.com/sponsors/RawToast","type":"github"},"gitHead":"3c1a696828419de698a7d174fd7d145f4cc3ae8f","scripts":{"lint":"oxlint check","test":"bun test","build":"bun build src/index.ts --outdir dist --target bun --external zod && bun build src/cli.ts --outdir dist --target bun --external zod && cp types/index.d.ts dist/","compile":"tsgo --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1e721df6-bd07-438b-9f62-02eb33d51b70"}},"repository":{"url":"git+https://github.com/RawToast/bun-scan.git","type":"git"},"_npmVersion":"11.6.2","description":"Vulnerability scanner for Bun projects","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"4.3.5"},"_hasShrinkwrap":false,"devDependencies":{"bun-types":"1.3.6","@repo/core":"workspace:*","@types/bun":"1.3.6","@repo/source-npm":"workspace:*","@repo/source-osv":"workspace:*","@typescript/native-preview":"7.0.0-dev.20260114.1"},"_npmOperationalInternal":{"tmp":"tmp/bun-scan_1.1.0-beta.4_1768712021193_0.47450722767612263","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"bun-scan","version":"1.1.0","keywords":["audit","bun","dependencies","osv","scanner","security","security-scanner","vulnerability","vulnerability-scanner"],"author":{"name":"rawtoast"},"license":"MIT","_id":"bun-scan@1.1.0","maintainers":[{"name":"namatoast","email":"jmorris@itazuramono.com"}],"homepage":"https://github.com/RawToast/bun-scan","bugs":{"url":"https://github.com/RawToast/bun-scan/issues"},"bin":{"bun-scan":"dist/cli.js"},"dist":{"shasum":"7d1d411b00f73593566b8b8d73efad5ce51fdc26","tarball":"https://registry.npmjs.org/bun-scan/-/bun-scan-1.1.0.tgz","fileCount":4,"integrity":"sha512-2u+uicSSiHm5BQkF97zKMb3KtWLZyTnF7SZQ3IMNQDFYTUyjJwQkDpU4fGQ0BBOs6Uj4VtNtNoAR15v67sxnZA==","signatures":[{"sig":"MEUCIQD3BNsqu/E4fz9yAjXdgy+iKT+TGtmV2cUcc7LtvlKb6wIgJBnbwY3Z5tqO/aiE62QEWyivXpZ4XtUuwU9jjY32XQY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/bun-scan@1.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":110552},"type":"module","types":"./dist/index.d.ts","engines":{"bun":">=1.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"funding":{"url":"https://github.com/sponsors/RawToast","type":"github"},"gitHead":"82aebda39bb66795bd037186d8ef400cdb82f54c","scripts":{"lint":"oxlint check","test":"bun test","build":"bun build src/index.ts --outdir dist --target bun --external zod && bun build src/cli.ts --outdir dist --target bun --external zod && cp types/index.d.ts dist/","compile":"tsgo --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1e721df6-bd07-438b-9f62-02eb33d51b70"}},"repository":{"url":"git+https://github.com/RawToast/bun-scan.git","type":"git"},"_npmVersion":"11.6.2","description":"Vulnerability scanner for Bun projects","directories":{},"_nodeVersion":"24.12.0","dependencies":{"zod":"4.3.5"},"_hasShrinkwrap":false,"devDependencies":{"bun-types":"1.3.6","@repo/core":"workspace:*","@types/bun":"1.3.6","@repo/source-npm":"workspace:*","@repo/source-osv":"workspace:*","@typescript/native-preview":"7.0.0-dev.20260114.1"},"_npmOperationalInternal":{"tmp":"tmp/bun-scan_1.1.0_1768724455253_0.38132561605585247","host":"s3://npm-registry-packages-npm-production"}},"1.1.1-beta.1":{"name":"bun-scan","version":"1.1.1-beta.1","keywords":["audit","bun","dependencies","osv","scanner","security","security-scanner","vulnerability","vulnerability-scanner"],"author":{"name":"rawtoast"},"license":"MIT","_id":"bun-scan@1.1.1-beta.1","maintainers":[{"name":"namatoast","email":"jmorris@itazuramono.com"}],"homepage":"https://github.com/RawToast/bun-scan","bugs":{"url":"https://github.com/RawToast/bun-scan/issues"},"bin":{"bun-scan":"dist/cli.js"},"dist":{"shasum":"2763c443b302fe1fd238734b960ce78e14cbdf15","tarball":"https://registry.npmjs.org/bun-scan/-/bun-scan-1.1.1-beta.1.tgz","fileCount":5,"integrity":"sha512-sBH6CQb/XfK0EKSEn9ZTQcLLLYIzmB0y/kPNHe1nsY5/GlkWjysBflPJOKomGBS1mgcaxR2vifOS7jm527Nn8Q==","signatures":[{"sig":"MEQCIE+HMOkm4ySeQ+2oXQrni8Oq0hFzgGGp5CZbGEacDxrYAiAW4EmKv3fqEJ+q6nNXZ2OPKXYY1YNap2NkmNscPuVeOw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/bun-scan@1.1.1-beta.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":129404},"type":"module","types":"./dist/index.d.ts","engines":{"bun":">=1.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"funding":{"url":"https://github.com/sponsors/RawToast","type":"github"},"gitHead":"56f33aca4dccd02635da22cc7254c345749dd935","scripts":{"lint":"oxlint check","test":"bun test","build":"bun build src/index.ts --outdir dist --target bun --external zod && bun build src/cli.ts --outdir dist --target bun --external zod && cp types/index.d.ts dist/","compile":"tsgo --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:59f3c194-d7cf-4f10-a871-b78eccd034b0"}},"repository":{"url":"git+https://github.com/RawToast/bun-scan.git","type":"git"},"_npmVersion":"11.9.0","description":"Vulnerability scanner for Bun projects","directories":{},"_nodeVersion":"24.14.0","dependencies":{"zod":"4.3.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"bun-types":"1.3.8","@repo/core":"workspace:*","@types/bun":"1.3.8","@repo/source-npm":"workspace:*","@repo/source-osv":"workspace:*","@typescript/native-preview":"7.0.0-dev.20260131.1"},"_npmOperationalInternal":{"tmp":"tmp/bun-scan_1.1.1-beta.1_1773242677537_0.587711111252893","host":"s3://npm-registry-packages-npm-production"}},"1.1.1-beta.2":{"name":"bun-scan","version":"1.1.1-beta.2","keywords":["audit","bun","dependencies","osv","scanner","security","security-scanner","vulnerability","vulnerability-scanner"],"author":{"name":"rawtoast"},"license":"MIT","_id":"bun-scan@1.1.1-beta.2","maintainers":[{"name":"namatoast","email":"jmorris@itazuramono.com"}],"homepage":"https://github.com/RawToast/bun-scan","bugs":{"url":"https://github.com/RawToast/bun-scan/issues"},"bin":{"bun-scan":"dist/cli.js"},"dist":{"shasum":"d1bcd6be64266a45d64e04f81561b785698b0448","tarball":"https://registry.npmjs.org/bun-scan/-/bun-scan-1.1.1-beta.2.tgz","fileCount":5,"integrity":"sha512-Z4pNYwvjfLazmPJJOzWZ3qGDMJ94cneC+gKCphr+8jXExoAjq9f+yWEfL520XBDlSWzS1t9+c7DKkmT8dmBmDA==","signatures":[{"sig":"MEYCIQDIf9K3QqPLKT71sGsFoilcXfjDiuP40LPJoHSN0HB6/AIhALmmZBZSlaNdMpzsRUztk3xM7gAPW+7tgoQrZ+3EeRps","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/bun-scan@1.1.1-beta.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":129406},"type":"module","types":"./dist/index.d.ts","engines":{"bun":">=1.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"funding":{"url":"https://github.com/sponsors/RawToast","type":"github"},"gitHead":"f56e379fde4a43ae765dfe5a9c194f122cf06cc1","scripts":{"lint":"oxlint check","test":"bun test","build":"bun build src/index.ts --outdir dist --target bun --external zod && bun build src/cli.ts --outdir dist --target bun --external zod && cp types/index.d.ts dist/","compile":"tsgo --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:59f3c194-d7cf-4f10-a871-b78eccd034b0"}},"repository":{"url":"git+https://github.com/RawToast/bun-scan.git","type":"git"},"_npmVersion":"11.11.0","description":"Vulnerability scanner for Bun projects","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"4.3.6"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"bun-types":"1.3.11","@repo/core":"workspace:*","@types/bun":"1.3.11","@repo/source-npm":"workspace:*","@repo/source-osv":"workspace:*","@typescript/native-preview":"7.0.0-dev.20260407.1"},"_npmOperationalInternal":{"tmp":"tmp/bun-scan_1.1.1-beta.2_1775557780172_0.42286811053279627","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"name":"bun-scan","version":"1.1.2","description":"Vulnerability scanner for Bun projects","keywords":["audit","bun","dependencies","osv","scanner","security","security-scanner","vulnerability","vulnerability-scanner"],"homepage":"https://github.com/RawToast/bun-scan","bugs":{"url":"https://github.com/RawToast/bun-scan/issues"},"license":"MIT","author":{"name":"rawtoast"},"repository":{"type":"git","url":"git+https://github.com/RawToast/bun-scan.git"},"funding":{"type":"github","url":"https://github.com/sponsors/RawToast"},"bin":{"bun-scan":"dist/cli.js"},"type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"build":"bun build src/index.ts --outdir dist --target bun --external zod && bun build src/cli.ts --outdir dist --target bun --external zod && cp types/index.d.ts dist/","prepublishOnly":"bun run build","compile":"tsgo --noEmit","test":"bun test","lint":"oxlint check"},"dependencies":{"zod":"4.3.6"},"devDependencies":{"@repo/core":"workspace:*","@repo/source-npm":"workspace:*","@repo/source-osv":"workspace:*","@types/bun":"1.3.11","@typescript/native-preview":"7.0.0-dev.20260407.1","bun-types":"1.3.11"},"engines":{"bun":">=1.0.0"},"gitHead":"54f258259b76e453f0b185ff5b97a994d4c7394c","_id":"bun-scan@1.1.2","_nodeVersion":"24.14.1","_npmVersion":"11.11.0","dist":{"integrity":"sha512-7hft4zQPUxq1zDN5v0OF2s3rnQCJ3v0QyrBxWnLLRcgGIkeiq1PmnpYCZzx3fS9FLWeV6vE97o9dVB9wsnW0ew==","shasum":"8477a4445f774d73105c909b32e549322d51ef3b","tarball":"https://registry.npmjs.org/bun-scan/-/bun-scan-1.1.2.tgz","fileCount":5,"unpackedSize":129399,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/bun-scan@1.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIAgQs3iicjVJ+cz0bRPHI184nqhf1FuYamuI0MfmFHhkAiEAibGq4fizdKGPbR2Tzs/mDqC5QJSuLl0XobkTTq6V79w="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:59f3c194-d7cf-4f10-a871-b78eccd034b0"}},"directories":{},"maintainers":[{"name":"namatoast","email":"jmorris@itazuramono.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/bun-scan_1.1.2_1775782543907_0.2131239617238152"},"_hasShrinkwrap":false}},"time":{"created":"2026-01-15T04:03:17.737Z","modified":"2026-04-10T00:55:44.410Z","1.0.1":"2026-01-15T04:03:18.322Z","1.1.0-beta.1":"2026-01-17T07:48:50.567Z","1.1.0-beta.2":"2026-01-18T04:00:41.930Z","1.1.0-beta.3":"2026-01-18T04:11:14.812Z","1.1.0-beta.4":"2026-01-18T04:53:41.319Z","1.1.0":"2026-01-18T08:20:55.408Z","1.1.1-beta.1":"2026-03-11T15:24:37.676Z","1.1.1-beta.2":"2026-04-07T10:29:40.360Z","1.1.2":"2026-04-10T00:55:44.056Z"},"bugs":{"url":"https://github.com/RawToast/bun-scan/issues"},"author":{"name":"rawtoast"},"license":"MIT","homepage":"https://github.com/RawToast/bun-scan","keywords":["audit","bun","dependencies","osv","scanner","security","security-scanner","vulnerability","vulnerability-scanner"],"repository":{"type":"git","url":"git+https://github.com/RawToast/bun-scan.git"},"description":"Vulnerability scanner for Bun projects","maintainers":[{"name":"namatoast","email":"jmorris@itazuramono.com"}],"readme":"# Bun-Scan\n\nA security scanner for [Bun](https://bun.sh/) that checks packages for known vulnerabilities during installation.\n\n## Features\n\n- **Real-time Scanning**: Checks packages against configured sources (OSV, npm, or both) during installation\n- **Whitelists**: Specific warnings can be ignored\n- **Fail-safe**: Can configure non-critical advisories to not prevent installations\n\n## Installation\n\n```bash\n# Install as a dev dependency\nbun add -d bun-scan\n```\n\nAdd to your `bunfig.toml`:\n\n```toml\n[install.security]\nscanner = \"bun-scan\"\n```\n\nSelect your source from `npm`, `osv` (default), or run checks against `both` by setting up your config in `.bun-scan.config.json`\n\nNote to set the schema version in the URL to the correct version:\n\n```json\n{\n  \"$schema\": \"https://raw.githubusercontent.com/rawtoast/bun-scan/v1.1.0/schema/bun-scan.schema.json\",\n  \"source\": \"npm\"\n}\n```\n\n### Ignoring Vulnerabilities\n\nA package may have a vulnerability, but your project is not affected. In this scenario, you would\nnot want installations to be prevented. To work around this, the vulnerability can be flagged as ignored in your `.bun-scan.config.json`\n\n```json\n{\n  \"$schema\": \"https://raw.githubusercontent.com/rawtoast/bun-scan/v1.1.0/schema/bun-scan.schema.json\",\n  \"source\": \"npm\",\n  \"packages\": {\n    \"hono\": {\n      \"vulnerabilities\": [\"CVE-2026-22818\"],\n      \"reason\": \"Project does not use JWT from hono, verify again in June\",\n      \"until\": \"2026-06-01\"\n    }\n  }\n}\n```\n\nNote that `bunReportWarnings` can be set `false` to print warning-level advisories without triggering Bun's install prompt:\n\n```json\n{\n  \"bunReportWarnings\": false\n}\n```\n\n### Advisory Levels\n\n#### Fatal (Installation Blocked)\n\n- **CVSS Score**: ≥ 7.0 (High/Critical)\n- **Database Severity**: CRITICAL or HIGH\n- **Action**: Installation is immediately blocked\n\n#### Warning (User Prompted)\n\n- **CVSS Score**: < 7.0 (Medium/Low)\n- **Database Severity**: MEDIUM, LOW, or unspecified\n- **Action**: User is prompted to continue or cancel\n\n## License\n\nMIT License - see the [LICENSE](LICENSE) file for details.\n\n## Acknowledgments\n\n- **maloma7**: For the original implementation of the Bun OSV Scanner\n\n## Related Projects\n\n- [Bun Security Scanner API](https://bun.com/docs/install/security-scanner-api)\n- [OSV.dev](https://osv.dev/)\n- [GitHub advisories](https://github.com/advisories)\n- [Bun OSV Scanner](https://github.com/bun-security-scanner/osv)\n- [Bun NPM Scanner](https://github.com/bun-security-scanner/npm)\n","readmeFilename":"README.md"}