Bun 1.4.3 adds bun check, a built-in TypeScript type checker, and expands support for running type checks before scripts, tests and builds. The release also updates networking, build performance and Node.js compatibility, alongside a large set of bug and security fixes.

Type-checking without installing TypeScript

bun check is based on typescript-go. It reads tsconfig.json, uses every CPU core and reports errors in the same format as tsc. Bun says it does not require the typescript package and passes TypeScript 7.0.2’s full conformance suite. The project’s published benchmarks, run on a 16-core Apple silicon Mac, report speeds 3–6.4 times higher and memory use 2.2–4.9 times lower than tsc 7.0.2; those figures are Bun’s measurements, not independent results.

The checker only performs type checks: it does not emit JavaScript or .d.ts files and does not provide a language server. Editors therefore continue using TypeScript for editor features. Type checks can also be combined with execution: bun run --check checks before running a script, bun test --check checks test files before running tests, and bun build --check stops a build if it finds a type error. Bun.build accepts check: true.

Bun says its tests compare results against tsc across conformance tests, deliberately misconfigured open-source projects, fuzzing and mutation tests. The release notes report one mismatch among 72 projects tested under default compiler options, and 191 mismatches across more than three million programs in offline fuzzing. Bun attributes 162 of those fuzzing mismatches to code that refers to itself while it is being declared. Details and usage instructions are in the bun check documentation; reported discrepancies can be filed as Bun issues.

Runtime and build changes

Bun.FetchSession gives a group of requests its own TLS, proxy and keep-alive settings and connection pool. Sessions do not share connections with each other or with plain fetch(). Proxy handling also improves: NO_PROXY now accepts wildcards, CIDR blocks, bare IPv6 addresses and host-port entries, while ALL_PROXY is used when HTTP_PROXY and HTTPS_PROXY are unset. A refused proxy CONNECT now causes fetch() to reject with ERR_PROXY_TUNNEL, including the proxy’s status and headers.

The experimental Bun.ModuleGraph runs multiple instances of an app in one process with separate module state, caches, timers and I/O. Bun explicitly says it is not a security sandbox. The Node.js --disallow-code-generation-from-strings flag now blocks eval() and new Function(); Bun’s =strict mode additionally blocks other string-to-code paths.

For responses larger than 16 KB, Bun says node:http and Bun.serve now send data in one write per tick rather than up to 16. In Bun’s benchmarks, a direct Bun.serve stream writing four 16 KB chunks was 83% faster; small responses are unchanged. Other changes include configurable compression levels for CompressionStream, If-Range support in Bun.serve, and lower peak memory for builds with many entry points. Compiled bytecode builds can use profiles to arrange frequently used code earlier in the executable; Bun reports that one large CLI’s cold start fell from 1.01 seconds to 0.53 seconds with this method.

In bun install, packages that will not be installed are no longer downloaded as tarballs when there is no lockfile. The release also updates JavaScriptCore and includes numerous fixes across the runtime, bundler, test runner, streams, TLS and Node.js compatibility. Security fixes include stricter TLS certificate checks and tighter validation of registry and tarball URLs before credentials are attached.