Bun 73,307 first wrote bun.lockb, a binary lockfile that no one could review in a pull request. Bun 1.2 (January 2025) replaced it with bun.lock, text in JSON-with-trailing-commas form, one line per package.
{
"lockfileVersion": 2,
"configVersion": 1,
"workspaces": { ... },
"packages": {
"content-type": ["content-type@1.0.5", "", {}, "sha512-nTjqfcBFEipKdXCv4YDQWCfmcLZKm81l..."],
"body-parser/content-type": ["content-type@2.1.0", "", {}, "sha512-mj7UPXE0jaqaOsukNZRUE..."],
...Each entry holds the resolved name@version, a registry field (empty for the default), metadata and the integrity hash. Keys are package names, and a nested copy is keyed by its parent's path. Bun also converts other package managers' lockfiles.
cd ~/v5-ch1 && mkdir bun-mig-npm bun-mig-classic bun-mig-berry
cp booknest/{package.json,package-lock.json} bun-mig-npm/
cp yarn-classic/{package.json,yarn.lock} bun-mig-classic/
cp yarn-demo/{package.json,yarn.lock} bun-mig-berry/
for d in bun-mig-npm bun-mig-classic bun-mig-berry; do (cd $d && bun pm migrate); doneOutput
[0.74ms] migrated lockfile from package-lock.json [805.23ms] migrated lockfile from yarn.lock error: failed to migrate lockfile: UnsupportedYarnLockfileVersion
npm 2,036 's, Yarn Classic 11,798 's and pnpm 69,400 's lockfiles convert with their versions kept; Yarn Berry 11,798 's is refused, so a Berry project must re-resolve. In CI, use bun ci (bun install --frozen-lockfile), which fails if package.json and bun.lock disagree.