How Bun’s Text Lockfile Cuts Supply-Chain Risks by Enabling CI Policy Scans
The new default lockfile in Bun v1.2 is a plain-text bun.lock, replacing the opaque bun.lockb. This change lets reviewers see exact version shifts, run policy checks in CI, and trace malicious inserts with standard git tools.