Announcing Bun and vlt Support in Socket

Bringing supply chain security to the next generation of JavaScript package managers

  • Ricky Reusser
    Ricky Reusser
  • Eli Insua
    Eli Insua
3 min read
Announcing Bun and vlt Support in Socket

Today we're announcing beta support for Bun and vlt package managers in Socket. Teams using these cutting-edge tools can now get the same comprehensive supply chain protection and SBOM accuracy they expect from Socket, without waiting for the ecosystem to catch up.

If you're building with Bun or vlt, Socket now has you covered.

Supporting Emerging JavaScript Package Managers

The JavaScript ecosystem has always moved quickly. New ideas in package management regularly reshape how developers install dependencies, optimize workflows, and think about security.

Early support for emerging tooling has always been part of our commitment to the JavaScript community. In addition to npm and Yarn, Socket was one of the first platforms to provide full supply chain security coverage for pnpm, well before tooling like Dependabot and most security vendors. In the Python ecosystem, Socket was the first to support the new pylock.toml standard and uv.lock files.

The newest additions to the JavaScript landscape are Bun, known for exceptional performance and a comprehensive standard library, and vlt, a modern package manager that introduces a serverless self-hosted registry approach and thoughtful security features.

New package managers become truly useful when they are supported across the full development ecosystem. CI systems, analysis tools, and security platforms need to understand their lockfile formats, dependency graphs, and resolution rules. Without that support, adoption can be risky and visibility into package behavior becomes inconsistent.

By adding beta support for Bun and vlt, Socket ensures that teams exploring these modern tools do not need to choose between innovation and supply chain protection.

How Socket Supports Bun and vlt

Socket automatically detects bun.lock and vlt-lock.json files, and analyzes dependency graphs in the same way it does for npm, pnpm, and Yarn. Once a lockfile is committed, Socket scans the project, surfaces dependency scores, and highlights risks directly in the dashboard.

The screenshot above shows a simple project containing a bun.lock file. After the lockfile is committed, Socket reads the dependency graph and displays associated scores and alerts without requiring any additional configuration.

What This Beta Includes

Socket's beta support for Bun and vlt includes:

  • Bun lockfile version 1 (bun.lock) and vlt lockfile version 0 (vlt-lock.json)
  • Full dependency graph analysis
  • Supply chain threat detection
  • Vulnerability scanning
  • SBOM generation
  • Real-time security monitoring

Current limitations: Socket does not yet support binary Bun lockfiles or legacy version 0 Bun lockfiles. We're working to expand format support based on user feedback during the beta period.

Getting Started

To try Bun or vlt support today, commit a supported lockfile to your repository. Socket will detect it automatically and begin scanning your project.

From there, you can explore dependency risks, inspect transitive graphs, and track supply chain posture just as you would with npm, pnpm, or Yarn.

If your team is adopting Bun or vlt at scale, we encourage you to try the beta and share feedback. Your input will help guide improvements and shape the future of support for these ecosystems.

Early Support Removes Adoption Barriers

The JavaScript ecosystem serves billions of people every day, powering web applications that run healthcare systems, financial infrastructure, educational platforms, and countless other critical services. When new package managers like Bun and vlt emerge with better security models or faster performance, the ecosystem benefits - but only if teams can actually adopt them.

We're rolling this out early because teams shouldn't have to wait six months or a year for security coverage while new package managers gain adoption. Security tooling needs to keep pace with innovation, not lag behind it.

Socket team members maintain npm packages responsible for more than 10% of all downloads across the entire registry. That level of involvement gives us a clear view into how the ecosystem evolves and a responsibility to help ensure it remains secure and resilient. When the ecosystem introduces new tooling that pushes JavaScript forward, we want to support that work so teams can adopt these tools without hesitation.

By supporting Bun and vlt early, we're ensuring that developers can adopt emerging package managers without losing the confidence, monitoring, and SBOM accuracy they rely on.

Stay ahead of threats

Subscribe to our newsletter

Get notified when we publish new security blog posts!