Claude Bot 40200931fd fix(security): prevent symlink chain path traversal in archive extraction
Chained symlinks in a tarball could escape the extraction directory.
The existing isSymlinkTargetSafe() validates symlink targets against
logical archive paths but doesn't consider the actual filesystem state
created by previously extracted entries. A chain of individually-safe
symlinks (e.g., x/a -> ., x/a/b -> ., x/a/b/c -> ../..) can combine
to resolve outside the extraction boundary.

Add isResolvedPathSafe() which uses realpath to verify the actual
filesystem resolution stays within the extraction directory. Apply this
check after creating symlinks (removing unsafe ones) and before creating
files or directories (skipping entries whose parent escapes).

Co-Authored-By: Claude <noreply@anthropic.com>
2026-02-12 04:57:49 +00:00
2026-02-03 22:18:40 -08:00
2025-11-28 17:51:45 +11:00
2026-01-25 10:38:13 -08:00
2026-02-03 22:18:40 -08:00
2025-12-18 18:03:23 -08:00
2026-01-18 00:17:14 -08:00
2025-11-25 11:06:24 -08:00
2026-02-08 01:32:25 -08:00
2026-02-08 01:32:25 -08:00
2025-07-10 00:10:43 -07:00

Logo

Bun

stars Bun speed

Documentation   •   Discord   •   Issues   •   Roadmap

Read the docs →

What is Bun?

Bun is an all-in-one toolkit for JavaScript and TypeScript apps. It ships as a single executable called bun.

At its core is the Bun runtime, a fast JavaScript runtime designed as a drop-in replacement for Node.js. It's written in Zig and powered by JavaScriptCore under the hood, dramatically reducing startup times and memory usage.

bun run index.tsx             # TS and JSX supported out-of-the-box

The bun command-line tool also implements a test runner, script runner, and Node.js-compatible package manager. Instead of 1,000 node_modules for development, you only need bun. Bun's built-in tools are significantly faster than existing options and usable in existing Node.js projects with little to no changes.

bun test                      # run tests
bun run start                 # run the `start` script in `package.json`
bun install <pkg>             # install a package
bunx cowsay 'Hello, world!'   # execute a package

Install

Bun supports Linux (x64 & arm64), macOS (x64 & Apple Silicon) and Windows (x64).

Linux users — Kernel version 5.6 or higher is strongly recommended, but the minimum is 5.1.

x64 users — if you see "illegal instruction" or similar errors, check our CPU requirements

# with install script (recommended)
curl -fsSL https://bun.com/install | bash

# on windows
powershell -c "irm bun.sh/install.ps1 | iex"

# with npm
npm install -g bun

# with Homebrew
brew tap oven-sh/bun
brew install bun

# with Docker
docker pull oven/bun
docker run --rm --init --ulimit memlock=-1:-1 oven/bun

Upgrade

To upgrade to the latest version of Bun, run:

bun upgrade

Bun automatically releases a canary build on every commit to main. To upgrade to the latest canary build, run:

bun upgrade --canary

View canary build

Guides

Contributing

Refer to the Project > Contributing guide to start contributing to Bun.

License

Refer to the Project > License page for information about Bun's licensing.

Description
Bun is a fast, incrementally adoptable all-in-one JavaScript, TypeScript & JSX toolkit. Use individual tools like bun test or bun install in Node.js projects, or adopt the complete stack with a fast JavaScript runtime, bundler, test runner, and package manager built in. Bun aims for 100% Node.js compatibility.
Readme 855 MiB
Languages
Zig 60.6%
C++ 24.8%
TypeScript 8.3%
C 3.3%
JavaScript 1.4%
Other 1.1%