Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 9 additions & 4 deletions docs/pm/cli/audit.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -72,30 +72,35 @@ The JSON is unfiltered — `--audit-level` and `--ignore` only affect the exit c
bun audit fix
```

Runs the audit, then upgrades each vulnerable package to the lowest non-vulnerable version that every dependent's range allows, and installs. Only `bun.lock` and `node_modules` change, with one exception: a direct dependency pinned to an exact version is treated as `^version`, and the pin in `package.json` (or the catalog entry) is rewritten if a fix is found.
Runs the audit, then upgrades each vulnerable package to the lowest non-vulnerable version that every dependent's range allows, and installs. Only `bun.lock` and `node_modules` change, with one exception: an exact version pin in your own `package.json` (a dependency, a catalog entry, or an [`overrides`](/pm/overrides) rule) is treated as `^version`, and the pin is rewritten if a fix is found.

```
fixing:
ms@0.7.0 → 0.7.1
lodash@4.17.20 → 4.17.21
package.json: 4.17.20 → 4.17.21
tar@6.1.11 → 6.1.12
package.json (overrides): 6.1.11 → 6.1.12

blocked by a dependent's range:
minimatch@0.3.0 → 3.0.2
express@3.21.2 depends on minimatch@0.3.0
semver@5.7.1 → 6.3.1
my-app depends on semver@^5.0.0
bun audit fix --latest
qs@6.5.2 → 6.11.0
package.json overrides qs@~6.5.0 (express>qs)
bun audit fix --latest

no published version fixes:
left-pad@1.3.0 GHSA-xxxx-xxxx-xxxx
bun audit fix --ignore GHSA-xxxx-xxxx-xxxx

Fixed 2 vulnerabilities in 2 packages
Fixed 3 vulnerabilities in 3 packages
5 vulnerabilities remaining
```

- **blocked by a dependent's range** — no safe version fits a dependent's declared range. If the range is in your own `package.json` or catalog, `bun audit fix --latest` gets past it. Otherwise, update the dependent or add an [`overrides`](/pm/overrides) entry.
- **blocked by a dependent's range** — no safe version fits a dependent's declared range. If the range is your own (a `package.json` dependency, a catalog entry, or an `overrides` rule, the last reported as `package.json overrides ...` followed by the rule's key when it is scoped), `bun audit fix --latest` gets past it. Otherwise, update the dependent or add an [`overrides`](/pm/overrides) entry.
- **no published version fixes** — every published version is vulnerable. Replace the package, or silence the advisory with the printed `--ignore` command.
- If no newer version is safe but an older one is, Bun downgrades and marks the row `(downgrade)`.
- A safe version newer than `--minimum-release-age` is still installed, marked `(newer than --minimum-release-age)`.
Expand All @@ -112,7 +117,7 @@ Fixed 2 vulnerabilities in 2 packages
bun audit fix --latest
```

Same as `bun audit fix`, but ranges in your own `package.json` files and catalogs no longer block a fix — they are rewritten to accept the new version, keeping their style (`^5.0.0` → `^6.3.1`, `~5.7.1` → `~6.3.1`, exact stays exact). Ranges declared by third-party packages still block; use `overrides` for those.
Same as `bun audit fix`, but ranges in your own `package.json` files, catalogs, and `overrides` no longer block a fix — they are rewritten to accept the new version, keeping their style (`^5.0.0` → `^6.3.1`, `~5.7.1` → `~6.3.1`, exact stays exact). Ranges declared by third-party packages still block; use `overrides` for those.

### Exit code

Expand Down
Loading