The bun.lock Lockfile

Bun 73,307 first wrote bun.lockb, a binary lockfile that no one could review in a pull request. Bun 1.2 (January 2025) replaced it with bun.lock, text in JSON-with-trailing-commas form, one line per package.

Excerpt from BookNest's bun.lockShell
{
  "lockfileVersion": 2,
  "configVersion": 1,
  "workspaces": { ... },
  "packages": {
    "content-type": ["content-type@1.0.5", "", {}, "sha512-nTjqfcBFEipKdXCv4YDQWCfmcLZKm81l..."],
    "body-parser/content-type": ["content-type@2.1.0", "", {}, "sha512-mj7UPXE0jaqaOsukNZRUE..."],
    ...

Each entry holds the resolved name@version, a registry field (empty for the default), metadata and the integrity hash. Keys are package names, and a nested copy is keyed by its parent's path. Bun also converts other package managers' lockfiles.

Migrating npm, Yarn Classic and Yarn Berry lockfiles to bun.lockShell
cd ~/v5-ch1 && mkdir bun-mig-npm bun-mig-classic bun-mig-berry
cp booknest/{package.json,package-lock.json} bun-mig-npm/
cp yarn-classic/{package.json,yarn.lock} bun-mig-classic/
cp yarn-demo/{package.json,yarn.lock} bun-mig-berry/
for d in bun-mig-npm bun-mig-classic bun-mig-berry; do (cd $d && bun pm migrate); done
Output
[0.74ms] migrated lockfile from package-lock.json
[805.23ms] migrated lockfile from yarn.lock
error: failed to migrate lockfile: UnsupportedYarnLockfileVersion

npm 2,036 's, Yarn Classic 11,798 's and pnpm 69,400 's lockfiles convert with their versions kept; Yarn Berry 11,798 's is refused, so a Berry project must re-resolve. In CI, use bun ci (bun install --frozen-lockfile), which fails if package.json and bun.lock disagree.