feat(bun): Add orchestrion bun build plugin - #21410

Merged
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion
Jun 18, 2026
Merged

feat(bun): Add orchestrion bun build plugin#21410
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion plugin defined in server-utils, and create a plugin that Bun can use in bun build mode.

Note: this does not provide a plugin for use with bun run, because that feature is blocked by oven-sh/bun#31770

When that issue resolves, we can look into providing this for the bun runtime, likely with a version guard to avoid the footgun of removing CommonJS exports in some cases.

@isaacs
isaacs requested a review from a team as a code ownerJune 9, 2026 19:23
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 9, 2026 19:24
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 362c870 to 39be3daCompareJune 9, 2026 19:28
@github-actions

github-actionsBot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.89 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.12 kB-0.02%-5 B 🔽
@sentry/browser (incl. Tracing, Profiling)50.67 kB--
@sentry/browser (incl. Tracing, Replay)85.08 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.69 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.78 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.45 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.18 kB--
@sentry/vue32.56 kB--
@sentry/vue (incl. Tracing)47.76 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.29 kB-0.02%-5 B 🔽
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.59 kB-0.01%-3 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.62 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.88 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback)91.46 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.71 kB-0.01%-1 B 🔽
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.08 kB-0.01%-4 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.06 kB-0.01%-4 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.95 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.91 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.65 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.6 kB-0.01%-4 B 🔽
@sentry/nextjs (client)50.58 kB--
@sentry/sveltekit (client)46.27 kB--
@sentry/core/server76.16 kB-0.01%-2 B 🔽
@sentry/core/browser63.31 kB-0.01%-2 B 🔽
@sentry/node-core61.87 kB-0.01%-2 B 🔽
@sentry/node126.78 kB+1.71%+2.13 kB 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.92 kB-0.01%-2 B 🔽
@sentry/node - without tracing74.23 kB-0.01%-2 B 🔽
@sentry/aws-serverless85.34 kB-0.01%-3 B 🔽
@sentry/cloudflare (withSentry) - minified174.48 kB-0.01%-4 B 🔽
@sentry/cloudflare (withSentry)436.52 kB-0.01%-23 B 🔽

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 39be3da to b34aa87CompareJune 10, 2026 19:34
Comment threadpackages/bun/package.json Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b34aa87 to 653fc0eCompareJune 10, 2026 20:06
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 653fc0e to 8743326CompareJune 15, 2026 18:48
Comment threadpackages/bun/src/plugin.ts Outdated
Comment threadpackages/bun/src/plugin.ts Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b5a794a to ac38662CompareJune 15, 2026 19:00
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ac38662 to 0cfd982CompareJune 15, 2026 19:46
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 0cfd982 to ccbd1b2CompareJune 15, 2026 22:45
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 568911f to 69a65aaCompareJune 18, 2026 04:51
Comment threadpackages/bun/src/plugin.ts
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 69a65aa to ea45a82CompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ea45a82 to 623d0c5CompareJune 18, 2026 14:27
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 623d0c5 to 2c1a850CompareJune 18, 2026 15:38
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 2c1a850 to 54e9bb3CompareJune 18, 2026 17:25

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 54e9bb3. Configure here.

Comment threadpackages/bun/package.json Outdated
Comment threadpackages/bun/package.json Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 54e9bb3 to 90c3233CompareJune 18, 2026 17:34
Base automatically changed from experiment/orchestrionjs-auto-instrumentation to developJune 18, 2026 17:38
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 90c3233 to a8f426cCompareJune 18, 2026 17:39
@isaacs
isaacs merged commit 974771b into developJun 18, 2026
516 of 528 checks passed
@isaacs
isaacs deleted the isaacs/bun-orchestrion branch June 18, 2026 21:20
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(bun): Add orchestrion bun build plugin - #21410

Merged
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion
Jun 18, 2026
Merged

feat(bun): Add orchestrion bun build plugin#21410
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion plugin defined in server-utils, and create a plugin that Bun can use in bun build mode.

Note: this does not provide a plugin for use with bun run, because that feature is blocked by oven-sh/bun#31770

When that issue resolves, we can look into providing this for the bun runtime, likely with a version guard to avoid the footgun of removing CommonJS exports in some cases.

@isaacs
isaacs requested a review from a team as a code ownerJune 9, 2026 19:23
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 9, 2026 19:24
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 362c870 to 39be3daCompareJune 9, 2026 19:28
@github-actions

github-actionsBot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.89 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.12 kB-0.02%-5 B 🔽
@sentry/browser (incl. Tracing, Profiling)50.67 kB--
@sentry/browser (incl. Tracing, Replay)85.08 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.69 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.78 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.45 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.18 kB--
@sentry/vue32.56 kB--
@sentry/vue (incl. Tracing)47.76 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.29 kB-0.02%-5 B 🔽
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.59 kB-0.01%-3 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.62 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.88 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback)91.46 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.71 kB-0.01%-1 B 🔽
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.08 kB-0.01%-4 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.06 kB-0.01%-4 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.95 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.91 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.65 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.6 kB-0.01%-4 B 🔽
@sentry/nextjs (client)50.58 kB--
@sentry/sveltekit (client)46.27 kB--
@sentry/core/server76.16 kB-0.01%-2 B 🔽
@sentry/core/browser63.31 kB-0.01%-2 B 🔽
@sentry/node-core61.87 kB-0.01%-2 B 🔽
@sentry/node126.78 kB+1.71%+2.13 kB 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.92 kB-0.01%-2 B 🔽
@sentry/node - without tracing74.23 kB-0.01%-2 B 🔽
@sentry/aws-serverless85.34 kB-0.01%-3 B 🔽
@sentry/cloudflare (withSentry) - minified174.48 kB-0.01%-4 B 🔽
@sentry/cloudflare (withSentry)436.52 kB-0.01%-23 B 🔽

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 39be3da to b34aa87CompareJune 10, 2026 19:34
Comment threadpackages/bun/package.json Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b34aa87 to 653fc0eCompareJune 10, 2026 20:06
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 653fc0e to 8743326CompareJune 15, 2026 18:48
Comment threadpackages/bun/src/plugin.ts Outdated
Comment threadpackages/bun/src/plugin.ts Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b5a794a to ac38662CompareJune 15, 2026 19:00
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ac38662 to 0cfd982CompareJune 15, 2026 19:46
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 0cfd982 to ccbd1b2CompareJune 15, 2026 22:45
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 568911f to 69a65aaCompareJune 18, 2026 04:51
Comment threadpackages/bun/src/plugin.ts
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 69a65aa to ea45a82CompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ea45a82 to 623d0c5CompareJune 18, 2026 14:27
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 623d0c5 to 2c1a850CompareJune 18, 2026 15:38
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 2c1a850 to 54e9bb3CompareJune 18, 2026 17:25

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 54e9bb3. Configure here.

Comment threadpackages/bun/package.json Outdated
Comment threadpackages/bun/package.json Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 54e9bb3 to 90c3233CompareJune 18, 2026 17:34
Base automatically changed from experiment/orchestrionjs-auto-instrumentation to developJune 18, 2026 17:38
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 90c3233 to a8f426cCompareJune 18, 2026 17:39
@isaacs
isaacs merged commit 974771b into developJun 18, 2026
516 of 528 checks passed
@isaacs
isaacs deleted the isaacs/bun-orchestrion branch June 18, 2026 21:20
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(bun): Add orchestrion bun build plugin - #21410

Merged
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion
Jun 18, 2026
Merged

feat(bun): Add orchestrion bun build plugin#21410
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion plugin defined in server-utils, and create a plugin that Bun can use in bun build mode.

Note: this does not provide a plugin for use with bun run, because that feature is blocked by oven-sh/bun#31770

When that issue resolves, we can look into providing this for the bun runtime, likely with a version guard to avoid the footgun of removing CommonJS exports in some cases.

@isaacs
isaacs requested a review from a team as a code ownerJune 9, 2026 19:23
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 9, 2026 19:24
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 362c870 to 39be3daCompareJune 9, 2026 19:28
@github-actions

github-actionsBot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.89 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.12 kB-0.02%-5 B 🔽
@sentry/browser (incl. Tracing, Profiling)50.67 kB--
@sentry/browser (incl. Tracing, Replay)85.08 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.69 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.78 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.45 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.18 kB--
@sentry/vue32.56 kB--
@sentry/vue (incl. Tracing)47.76 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.29 kB-0.02%-5 B 🔽
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.59 kB-0.01%-3 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.62 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.88 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback)91.46 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.71 kB-0.01%-1 B 🔽
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.08 kB-0.01%-4 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.06 kB-0.01%-4 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.95 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.91 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.65 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.6 kB-0.01%-4 B 🔽
@sentry/nextjs (client)50.58 kB--
@sentry/sveltekit (client)46.27 kB--
@sentry/core/server76.16 kB-0.01%-2 B 🔽
@sentry/core/browser63.31 kB-0.01%-2 B 🔽
@sentry/node-core61.87 kB-0.01%-2 B 🔽
@sentry/node126.78 kB+1.71%+2.13 kB 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.92 kB-0.01%-2 B 🔽
@sentry/node - without tracing74.23 kB-0.01%-2 B 🔽
@sentry/aws-serverless85.34 kB-0.01%-3 B 🔽
@sentry/cloudflare (withSentry) - minified174.48 kB-0.01%-4 B 🔽
@sentry/cloudflare (withSentry)436.52 kB-0.01%-23 B 🔽

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 39be3da to b34aa87CompareJune 10, 2026 19:34
Comment threadpackages/bun/package.json Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b34aa87 to 653fc0eCompareJune 10, 2026 20:06
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 653fc0e to 8743326CompareJune 15, 2026 18:48
Comment threadpackages/bun/src/plugin.ts Outdated
Comment threadpackages/bun/src/plugin.ts Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b5a794a to ac38662CompareJune 15, 2026 19:00
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ac38662 to 0cfd982CompareJune 15, 2026 19:46
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 0cfd982 to ccbd1b2CompareJune 15, 2026 22:45
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 568911f to 69a65aaCompareJune 18, 2026 04:51
Comment threadpackages/bun/src/plugin.ts
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 69a65aa to ea45a82CompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ea45a82 to 623d0c5CompareJune 18, 2026 14:27
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 623d0c5 to 2c1a850CompareJune 18, 2026 15:38
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 2c1a850 to 54e9bb3CompareJune 18, 2026 17:25

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 54e9bb3. Configure here.

Comment threadpackages/bun/package.json Outdated
Comment threadpackages/bun/package.json Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 54e9bb3 to 90c3233CompareJune 18, 2026 17:34
Base automatically changed from experiment/orchestrionjs-auto-instrumentation to developJune 18, 2026 17:38
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 90c3233 to a8f426cCompareJune 18, 2026 17:39
@isaacs
isaacs merged commit 974771b into developJun 18, 2026
516 of 528 checks passed
@isaacs
isaacs deleted the isaacs/bun-orchestrion branch June 18, 2026 21:20
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(bun): Add orchestrion bun build plugin - #21410

Merged
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion
Jun 18, 2026
Merged

feat(bun): Add orchestrion bun build plugin#21410
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion plugin defined in server-utils, and create a plugin that Bun can use in bun build mode.

Note: this does not provide a plugin for use with bun run, because that feature is blocked by oven-sh/bun#31770

When that issue resolves, we can look into providing this for the bun runtime, likely with a version guard to avoid the footgun of removing CommonJS exports in some cases.

@isaacs
isaacs requested a review from a team as a code ownerJune 9, 2026 19:23
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 9, 2026 19:24
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 362c870 to 39be3daCompareJune 9, 2026 19:28
@github-actions

github-actionsBot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.89 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.12 kB-0.02%-5 B 🔽
@sentry/browser (incl. Tracing, Profiling)50.67 kB--
@sentry/browser (incl. Tracing, Replay)85.08 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.69 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.78 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.45 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.18 kB--
@sentry/vue32.56 kB--
@sentry/vue (incl. Tracing)47.76 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.29 kB-0.02%-5 B 🔽
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.59 kB-0.01%-3 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.62 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.88 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback)91.46 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.71 kB-0.01%-1 B 🔽
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.08 kB-0.01%-4 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.06 kB-0.01%-4 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.95 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.91 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.65 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.6 kB-0.01%-4 B 🔽
@sentry/nextjs (client)50.58 kB--
@sentry/sveltekit (client)46.27 kB--
@sentry/core/server76.16 kB-0.01%-2 B 🔽
@sentry/core/browser63.31 kB-0.01%-2 B 🔽
@sentry/node-core61.87 kB-0.01%-2 B 🔽
@sentry/node126.78 kB+1.71%+2.13 kB 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.92 kB-0.01%-2 B 🔽
@sentry/node - without tracing74.23 kB-0.01%-2 B 🔽
@sentry/aws-serverless85.34 kB-0.01%-3 B 🔽
@sentry/cloudflare (withSentry) - minified174.48 kB-0.01%-4 B 🔽
@sentry/cloudflare (withSentry)436.52 kB-0.01%-23 B 🔽

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 39be3da to b34aa87CompareJune 10, 2026 19:34
Comment threadpackages/bun/package.json Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b34aa87 to 653fc0eCompareJune 10, 2026 20:06
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 653fc0e to 8743326CompareJune 15, 2026 18:48
Comment threadpackages/bun/src/plugin.ts Outdated
Comment threadpackages/bun/src/plugin.ts Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b5a794a to ac38662CompareJune 15, 2026 19:00
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ac38662 to 0cfd982CompareJune 15, 2026 19:46
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 0cfd982 to ccbd1b2CompareJune 15, 2026 22:45
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 568911f to 69a65aaCompareJune 18, 2026 04:51
Comment threadpackages/bun/src/plugin.ts
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 69a65aa to ea45a82CompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ea45a82 to 623d0c5CompareJune 18, 2026 14:27
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 623d0c5 to 2c1a850CompareJune 18, 2026 15:38
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 2c1a850 to 54e9bb3CompareJune 18, 2026 17:25

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 54e9bb3. Configure here.

Comment threadpackages/bun/package.json Outdated
Comment threadpackages/bun/package.json Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 54e9bb3 to 90c3233CompareJune 18, 2026 17:34
Base automatically changed from experiment/orchestrionjs-auto-instrumentation to developJune 18, 2026 17:38
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 90c3233 to a8f426cCompareJune 18, 2026 17:39
@isaacs
isaacs merged commit 974771b into developJun 18, 2026
516 of 528 checks passed
@isaacs
isaacs deleted the isaacs/bun-orchestrion branch June 18, 2026 21:20
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(bun): Add orchestrion bun build plugin - #21410

Merged
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion
Jun 18, 2026
Merged

feat(bun): Add orchestrion bun build plugin#21410
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion plugin defined in server-utils, and create a plugin that Bun can use in bun build mode.

Note: this does not provide a plugin for use with bun run, because that feature is blocked by oven-sh/bun#31770

When that issue resolves, we can look into providing this for the bun runtime, likely with a version guard to avoid the footgun of removing CommonJS exports in some cases.

@isaacs
isaacs requested a review from a team as a code ownerJune 9, 2026 19:23
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 9, 2026 19:24
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 362c870 to 39be3daCompareJune 9, 2026 19:28
@github-actions

github-actionsBot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.89 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.12 kB-0.02%-5 B 🔽
@sentry/browser (incl. Tracing, Profiling)50.67 kB--
@sentry/browser (incl. Tracing, Replay)85.08 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.69 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.78 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.45 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.18 kB--
@sentry/vue32.56 kB--
@sentry/vue (incl. Tracing)47.76 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.29 kB-0.02%-5 B 🔽
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.59 kB-0.01%-3 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.62 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.88 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback)91.46 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.71 kB-0.01%-1 B 🔽
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.08 kB-0.01%-4 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.06 kB-0.01%-4 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.95 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.91 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.65 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.6 kB-0.01%-4 B 🔽
@sentry/nextjs (client)50.58 kB--
@sentry/sveltekit (client)46.27 kB--
@sentry/core/server76.16 kB-0.01%-2 B 🔽
@sentry/core/browser63.31 kB-0.01%-2 B 🔽
@sentry/node-core61.87 kB-0.01%-2 B 🔽
@sentry/node126.78 kB+1.71%+2.13 kB 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.92 kB-0.01%-2 B 🔽
@sentry/node - without tracing74.23 kB-0.01%-2 B 🔽
@sentry/aws-serverless85.34 kB-0.01%-3 B 🔽
@sentry/cloudflare (withSentry) - minified174.48 kB-0.01%-4 B 🔽
@sentry/cloudflare (withSentry)436.52 kB-0.01%-23 B 🔽

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 39be3da to b34aa87CompareJune 10, 2026 19:34
Comment threadpackages/bun/package.json Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b34aa87 to 653fc0eCompareJune 10, 2026 20:06
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 653fc0e to 8743326CompareJune 15, 2026 18:48
Comment threadpackages/bun/src/plugin.ts Outdated
Comment threadpackages/bun/src/plugin.ts Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b5a794a to ac38662CompareJune 15, 2026 19:00
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ac38662 to 0cfd982CompareJune 15, 2026 19:46
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 0cfd982 to ccbd1b2CompareJune 15, 2026 22:45
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 568911f to 69a65aaCompareJune 18, 2026 04:51
Comment threadpackages/bun/src/plugin.ts
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 69a65aa to ea45a82CompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ea45a82 to 623d0c5CompareJune 18, 2026 14:27
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 623d0c5 to 2c1a850CompareJune 18, 2026 15:38
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 2c1a850 to 54e9bb3CompareJune 18, 2026 17:25

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 54e9bb3. Configure here.

Comment threadpackages/bun/package.json Outdated
Comment threadpackages/bun/package.json Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 54e9bb3 to 90c3233CompareJune 18, 2026 17:34
Base automatically changed from experiment/orchestrionjs-auto-instrumentation to developJune 18, 2026 17:38
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 90c3233 to a8f426cCompareJune 18, 2026 17:39
@isaacs
isaacs merged commit 974771b into developJun 18, 2026
516 of 528 checks passed
@isaacs
isaacs deleted the isaacs/bun-orchestrion branch June 18, 2026 21:20
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(bun): Add orchestrion bun build plugin - #21410

Merged
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion
Jun 18, 2026
Merged

feat(bun): Add orchestrion bun build plugin#21410
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion plugin defined in server-utils, and create a plugin that Bun can use in bun build mode.

Note: this does not provide a plugin for use with bun run, because that feature is blocked by oven-sh/bun#31770

When that issue resolves, we can look into providing this for the bun runtime, likely with a version guard to avoid the footgun of removing CommonJS exports in some cases.

@isaacs
isaacs requested a review from a team as a code ownerJune 9, 2026 19:23
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 9, 2026 19:24
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 362c870 to 39be3daCompareJune 9, 2026 19:28
@github-actions

github-actionsBot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.89 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.12 kB-0.02%-5 B 🔽
@sentry/browser (incl. Tracing, Profiling)50.67 kB--
@sentry/browser (incl. Tracing, Replay)85.08 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.69 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.78 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.45 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.18 kB--
@sentry/vue32.56 kB--
@sentry/vue (incl. Tracing)47.76 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.29 kB-0.02%-5 B 🔽
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.59 kB-0.01%-3 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.62 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.88 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback)91.46 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.71 kB-0.01%-1 B 🔽
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.08 kB-0.01%-4 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.06 kB-0.01%-4 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.95 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.91 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.65 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.6 kB-0.01%-4 B 🔽
@sentry/nextjs (client)50.58 kB--
@sentry/sveltekit (client)46.27 kB--
@sentry/core/server76.16 kB-0.01%-2 B 🔽
@sentry/core/browser63.31 kB-0.01%-2 B 🔽
@sentry/node-core61.87 kB-0.01%-2 B 🔽
@sentry/node126.78 kB+1.71%+2.13 kB 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.92 kB-0.01%-2 B 🔽
@sentry/node - without tracing74.23 kB-0.01%-2 B 🔽
@sentry/aws-serverless85.34 kB-0.01%-3 B 🔽
@sentry/cloudflare (withSentry) - minified174.48 kB-0.01%-4 B 🔽
@sentry/cloudflare (withSentry)436.52 kB-0.01%-23 B 🔽

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 39be3da to b34aa87CompareJune 10, 2026 19:34
Comment threadpackages/bun/package.json Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b34aa87 to 653fc0eCompareJune 10, 2026 20:06
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 653fc0e to 8743326CompareJune 15, 2026 18:48
Comment threadpackages/bun/src/plugin.ts Outdated
Comment threadpackages/bun/src/plugin.ts Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b5a794a to ac38662CompareJune 15, 2026 19:00
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ac38662 to 0cfd982CompareJune 15, 2026 19:46
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 0cfd982 to ccbd1b2CompareJune 15, 2026 22:45
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 568911f to 69a65aaCompareJune 18, 2026 04:51
Comment threadpackages/bun/src/plugin.ts
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 69a65aa to ea45a82CompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ea45a82 to 623d0c5CompareJune 18, 2026 14:27
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 623d0c5 to 2c1a850CompareJune 18, 2026 15:38
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 2c1a850 to 54e9bb3CompareJune 18, 2026 17:25

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 54e9bb3. Configure here.

Comment threadpackages/bun/package.json Outdated
Comment threadpackages/bun/package.json Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 54e9bb3 to 90c3233CompareJune 18, 2026 17:34
Base automatically changed from experiment/orchestrionjs-auto-instrumentation to developJune 18, 2026 17:38
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 90c3233 to a8f426cCompareJune 18, 2026 17:39
@isaacs
isaacs merged commit 974771b into developJun 18, 2026
516 of 528 checks passed
@isaacs
isaacs deleted the isaacs/bun-orchestrion branch June 18, 2026 21:20
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(bun): Add orchestrion bun build plugin - #21410

Merged
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion
Jun 18, 2026
Merged

feat(bun): Add orchestrion bun build plugin#21410
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion plugin defined in server-utils, and create a plugin that Bun can use in bun build mode.

Note: this does not provide a plugin for use with bun run, because that feature is blocked by oven-sh/bun#31770

When that issue resolves, we can look into providing this for the bun runtime, likely with a version guard to avoid the footgun of removing CommonJS exports in some cases.

@isaacs
isaacs requested a review from a team as a code ownerJune 9, 2026 19:23
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 9, 2026 19:24
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 362c870 to 39be3daCompareJune 9, 2026 19:28
@github-actions

github-actionsBot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.89 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.12 kB-0.02%-5 B 🔽
@sentry/browser (incl. Tracing, Profiling)50.67 kB--
@sentry/browser (incl. Tracing, Replay)85.08 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.69 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.78 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.45 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.18 kB--
@sentry/vue32.56 kB--
@sentry/vue (incl. Tracing)47.76 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.29 kB-0.02%-5 B 🔽
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.59 kB-0.01%-3 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.62 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.88 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback)91.46 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.71 kB-0.01%-1 B 🔽
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.08 kB-0.01%-4 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.06 kB-0.01%-4 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.95 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.91 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.65 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.6 kB-0.01%-4 B 🔽
@sentry/nextjs (client)50.58 kB--
@sentry/sveltekit (client)46.27 kB--
@sentry/core/server76.16 kB-0.01%-2 B 🔽
@sentry/core/browser63.31 kB-0.01%-2 B 🔽
@sentry/node-core61.87 kB-0.01%-2 B 🔽
@sentry/node126.78 kB+1.71%+2.13 kB 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.92 kB-0.01%-2 B 🔽
@sentry/node - without tracing74.23 kB-0.01%-2 B 🔽
@sentry/aws-serverless85.34 kB-0.01%-3 B 🔽
@sentry/cloudflare (withSentry) - minified174.48 kB-0.01%-4 B 🔽
@sentry/cloudflare (withSentry)436.52 kB-0.01%-23 B 🔽

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 39be3da to b34aa87CompareJune 10, 2026 19:34
Comment threadpackages/bun/package.json Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b34aa87 to 653fc0eCompareJune 10, 2026 20:06
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 653fc0e to 8743326CompareJune 15, 2026 18:48
Comment threadpackages/bun/src/plugin.ts Outdated
Comment threadpackages/bun/src/plugin.ts Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b5a794a to ac38662CompareJune 15, 2026 19:00
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ac38662 to 0cfd982CompareJune 15, 2026 19:46
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 0cfd982 to ccbd1b2CompareJune 15, 2026 22:45
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 568911f to 69a65aaCompareJune 18, 2026 04:51
Comment threadpackages/bun/src/plugin.ts
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 69a65aa to ea45a82CompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ea45a82 to 623d0c5CompareJune 18, 2026 14:27
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 623d0c5 to 2c1a850CompareJune 18, 2026 15:38
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 2c1a850 to 54e9bb3CompareJune 18, 2026 17:25

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 54e9bb3. Configure here.

Comment threadpackages/bun/package.json Outdated
Comment threadpackages/bun/package.json Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 54e9bb3 to 90c3233CompareJune 18, 2026 17:34
Base automatically changed from experiment/orchestrionjs-auto-instrumentation to developJune 18, 2026 17:38
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 90c3233 to a8f426cCompareJune 18, 2026 17:39
@isaacs
isaacs merged commit 974771b into developJun 18, 2026
516 of 528 checks passed
@isaacs
isaacs deleted the isaacs/bun-orchestrion branch June 18, 2026 21:20
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(bun): Add orchestrion bun build plugin - #21410

Merged
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion
Jun 18, 2026
Merged

feat(bun): Add orchestrion bun build plugin#21410
isaacs merged 1 commit into
developfrom
isaacs/bun-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion plugin defined in server-utils, and create a plugin that Bun can use in bun build mode.

Note: this does not provide a plugin for use with bun run, because that feature is blocked by oven-sh/bun#31770

When that issue resolves, we can look into providing this for the bun runtime, likely with a version guard to avoid the footgun of removing CommonJS exports in some cases.

@isaacs
isaacs requested a review from a team as a code ownerJune 9, 2026 19:23
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 9, 2026 19:24
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 362c870 to 39be3daCompareJune 9, 2026 19:28
@github-actions

github-actionsBot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.89 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.12 kB-0.02%-5 B 🔽
@sentry/browser (incl. Tracing, Profiling)50.67 kB--
@sentry/browser (incl. Tracing, Replay)85.08 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.69 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.78 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.45 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.18 kB--
@sentry/vue32.56 kB--
@sentry/vue (incl. Tracing)47.76 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.29 kB-0.02%-5 B 🔽
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.59 kB-0.01%-3 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.62 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.88 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback)91.46 kB-0.01%-3 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.71 kB-0.01%-1 B 🔽
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.08 kB-0.01%-4 B 🔽
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.06 kB-0.01%-4 B 🔽
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.95 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.91 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.65 kB-0.01%-4 B 🔽
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.6 kB-0.01%-4 B 🔽
@sentry/nextjs (client)50.58 kB--
@sentry/sveltekit (client)46.27 kB--
@sentry/core/server76.16 kB-0.01%-2 B 🔽
@sentry/core/browser63.31 kB-0.01%-2 B 🔽
@sentry/node-core61.87 kB-0.01%-2 B 🔽
@sentry/node126.78 kB+1.71%+2.13 kB 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.92 kB-0.01%-2 B 🔽
@sentry/node - without tracing74.23 kB-0.01%-2 B 🔽
@sentry/aws-serverless85.34 kB-0.01%-3 B 🔽
@sentry/cloudflare (withSentry) - minified174.48 kB-0.01%-4 B 🔽
@sentry/cloudflare (withSentry)436.52 kB-0.01%-23 B 🔽

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 39be3da to b34aa87CompareJune 10, 2026 19:34
Comment threadpackages/bun/package.json Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b34aa87 to 653fc0eCompareJune 10, 2026 20:06
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 653fc0e to 8743326CompareJune 15, 2026 18:48
Comment threadpackages/bun/src/plugin.ts Outdated
Comment threadpackages/bun/src/plugin.ts Outdated
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from b5a794a to ac38662CompareJune 15, 2026 19:00
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ac38662 to 0cfd982CompareJune 15, 2026 19:46
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 0cfd982 to ccbd1b2CompareJune 15, 2026 22:45
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 568911f to 69a65aaCompareJune 18, 2026 04:51
Comment threadpackages/bun/src/plugin.ts
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 69a65aa to ea45a82CompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from ea45a82 to 623d0c5CompareJune 18, 2026 14:27
Comment threadpackages/bun/src/plugin.ts Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 623d0c5 to 2c1a850CompareJune 18, 2026 15:38
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 2c1a850 to 54e9bb3CompareJune 18, 2026 17:25

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 54e9bb3. Configure here.

Comment threadpackages/bun/package.json Outdated
Comment threadpackages/bun/package.json Outdated
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 54e9bb3 to 90c3233CompareJune 18, 2026 17:34
Base automatically changed from experiment/orchestrionjs-auto-instrumentation to developJune 18, 2026 17:38
Use the orchestrion plugin defined in server-utils, and create a plugin
that Bun can use in `bun build` mode.
Note: this does *not* provide a plugin for use with `bun run`, because
that feature is blocked by oven-sh/bun#31770
When that issue resolves, we can look into providing this for the bun
runtime, likely with a version guard to avoid the footgun of removing
CommonJS exports in some cases.
@isaacs
isaacsforce-pushed the isaacs/bun-orchestrion branch from 90c3233 to a8f426cCompareJune 18, 2026 17:39
@isaacs
isaacs merged commit 974771b into developJun 18, 2026
516 of 528 checks passed
@isaacs
isaacs deleted the isaacs/bun-orchestrion branch June 18, 2026 21:20
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264