Bun security scanner for SocketDev
npm install @socketsecurity/bun-security-scanner![]()
Official Socket Security scanner for Bun's package installation process. Protects your projects from malicious packages, typosquatting, and other supply chain attacks.
- 🛡️ Real-time security scanning during package installation
- 🔍 Detects malware, typosquatting, and supply chain attacks
- ⚡ Optimized batching for fast scans
- 🔐 Supports both authenticated (Socket org) and free modes
- 🎯 Native integration with Bun's security provider API
``bash`
bun add -d @socketsecurity/bun-security-scanner
Add to your bunfig.toml:
`toml`
[install.security]
scanner = "@socketsecurity/bun-security-scanner"
For enhanced scanning with your Socket organization settings, set the SOCKET_API_KEY environment variable:
`bash
export SOCKET_API_KEY="xyz"
bun install
`
> Note: required scope packages
The scanner will automatically read your token from:
1. SOCKET_API_KEY` environment variable
2. Socket CLI settings file (if available)
Without a token, the scanner runs in free mode using Socket's public API.
- Socket Documentation
- Bun Security Scanner API
- Report Issues