Conversation
…and per-reference inlining, input sourcemaps, --pass-with-no-tests, and output overwrite behavior
|
Warning Review limit reached
On-demand reviews are free for the next 12 days. After that, they cost $0.25 per reviewed file. Or wait 8 minutes for your next included review. View limit detailsLimit details: You’ve used all 10 included reviews currently available. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (7)
Comment |
|
Updated 4:23 AM PT - Sep 8th, 2026
✅ @robobun, your commit ecffda42b275f84af70eeead8b4745b3267be603 passed in 🧪 To try this PR locally: bunx bun-pr 41937That installs a local version of the PR into your bun-41937 --bun |
|
Status: docs only, no build needed. Every added sentence was checked against bun 1.4.3 with the commands listed under Notes in the PR body (release binary, linux x64). Behaviors that are bugs rather than limitations were deliberately kept out of the docs and are tracked in the PRs linked under Background. |
|
Heads-up for the |
…rcemap as inert there, active voice
There was a problem hiding this comment.
LGTM — the follow-up commit addressed all three points from the earlier review: --watch is out of the --no-bundle "apply" list and its idle behavior is stated in both build.mdx and the esbuild --watch row; --sourcemap and --format are now in the inert list; and the flagged passive-voice sentences across index.mdx, esbuild.mdx, standalone-html.mdx, and build.mdx now name Bun as the actor.
Re-checked the updated --no-bundle flag partition against the transform-only path in build_command.rs / transpiler.rs — the applied vs. ignored split matches. Confirmed the --allow-overwrite row now describes the actual overwrite behavior rather than the previous inverted claim. The new --pass-with-no-tests and --trust wording match their CLI behavior. No code changes; docs-only.
Extended reasoning...
Overview
Docs-only PR touching seven .mdx files under docs/: bundler comparison table (esbuild.mdx), bundler sourcemap section (index.mdx), standalone HTML limitations, and three CLI snippet pages (build, install, test) plus test/discovery.mdx. It documents behavioral caveats — --no-bundle flag scope, input-sourcemap non-composition, output overwrite behavior, standalone HTML asset duplication and CSP interaction, --pass-with-no-tests, --save-text-lockfile default, and --trust requiring named packages.
Security risks
None. Pure documentation prose; no executable code, config, types, or build scripts touched.
Level of scrutiny
Low-to-moderate. The main risk in a docs PR is factual inaccuracy. The prior review round traced the --no-bundle code path (build_command.rs transform-only branch, transpiler.rs printer entry) and flagged three issues; the new commit fixed all of them. The remaining claims (overwrite behavior, --trust no-op on bare install, --pass-with-no-tests exit codes, CSP/nonce dropping, per-reference asset embedding) were verified by the PR author with reproducible commands in the description and are consistent with the source paths examined during the earlier review.
Other factors
No CODEOWNERS entry covers docs/. Bug hunt exited on dry_streak with zero findings this round. No outstanding third-party CHANGES_REQUESTED reviews. The change corrects a documented statement that was the opposite of runtime behavior (the old --allow-overwrite row), which is a net correctness improvement worth landing.
The HTML tokenizer turns CRLF and lone CR into LF before the text of an inline element exists, so that is the text a browser hashes for CSP and a hash over raw CR bytes never matched. The CSS printer keeps CRLF in /*! */ comments and banner/footer text is written as given, so both reached the output. The single walker behind the byte count, the copy and the hash now applies that normalization too. Also drops the duplicate-asset docs bullet, which #41937 carries.
Problem
bun build --no-bundleaccepts--splitting,--external,--format,--banner,--footer,--sourcemap,--metafile,--bytecodeand silently ignores them, and--no-bundle --watchbuilds once and never rebuilds (bun build --watch --no-bundle does not reload on file changes #14519); a standalone HTML build copies a CSP<meta>through while droppingnonceand inlining everything; an asset referenced N times is embedded N times (200 KB PNG x5 = 1.37 MB page); input//# sourceMappingURLmaps are never composed;--pass-with-no-testsexists in--helpbut in no doc.docs/bundler/esbuild.mdx: "Bun never allows overwriting" (bun build ./in.js --outfile=in.jsreplaces the source file without a prompt, esbuild refuses without--allow-overwrite), and--watch"No differences" (esbuild watches transform-only builds,bun build --no-bundle --watchdoes not rebuild).Fix
snippets/cli/build.mdx: say which options apply under--no-bundle, which ones Bun accepts but ignores, what--watchdoes there, and that--bytecode-depthneeds--bytecode. The--watchentry points at it.bundler/standalone-html.mdxLimitations: per-reference inlining, and the CSP / dropped-nonceinteraction.bundler/index.mdxsourcemap section and bothesbuild.mdxsourcemap rows: Bun does not read input sourcemaps.esbuild.mdx--allow-overwriteand--watchrows: describe the real behavior.snippets/cli/test.mdxandtest/discovery.mdx: document--pass-with-no-testsand the exit code without it.snippets/cli/install.mdx:--save-text-lockfileis the default since 1.2,--trustonly acts on named packages.Background
docs/snippets/cli/*.mdxare the flag lists imported into the main pages (bundler/index.mdximportssnippets/cli/build.mdx), so a sentence there is what renders under "CLI Usage".--no-bundle --watchrebuilding (bun build: install a file watcher for --no-bundle --watch #35633),--no-bundle --sourcemap(bun build --no-bundle: honor --sourcemap #38651),--no-bundleexiting 0 on an unresolvable entry (bun build --no-bundle: exit 1 when an entry point does not resolve #38752), multi-candidatesrcset/imagesrcset(bundler(html): parse srcset into per-candidate imports #36012),--pass-with-no-testswith a missing path argument (bun test: honor --pass-with-no-tests when a single path argument does not exist #41924), input sourcemap composition itself (bundler: chain inline input sourcemaps through to output #30539, bundler: chain external input sourcemaps and thread chains through the dev server #32473), refusing to overwrite inputs (bundler: refuse to write an output file over one of the build's inputs #41612), and rewriting the CSP meta for standalone HTML (bundler: rewrite a Content-Security-Policy meta for what standalone HTML inlines #41954). Each of those changes a sentence added here; whichever lands second updates it. Relative-path--externalnot rebased,"1.0.0 || ^7"resolving to 1.0.0, andbun info pkg@unknown-tagprintinglatestare tracked separately without a docs change.Notes
Commands used to check each statement (bun 1.4.3, linux x64):
--no-bundleinert flags:bun build e.ts --no-bundle --banner='/*B*/' --footer='/*F*/' --metafile=meta.json --splitting --external=zzz --outdir=outexits 0, writesout/e.jswith no banner/footer and nometa.json.--format=cjsand--format=iifestill print ESM;--sourcemap=external|linked|inlinewrite no map.--define,--env,--drop,--loader,--jsx-*,--minify,--tsconfig-override,--outdir/--outfile/--root/--entry-namingall take effect.--compile --no-bundleerrors with "--compile does not support --no-bundle".--no-bundle --watch:bun build ./a.ts --no-bundle --watch --outdir out, then rewritea.ts(in place and by rename):out/a.jskeeps the first content and the log shows one "Transpiled file" line. The same steps without--no-bundlerebuild three times.--bytecode-depth=2without--bytecode: plain.jsoutput, exit 0.<meta http-equiv="Content-Security-Policy" content="script-src 'self' 'nonce-abc'">plus<script nonce="abc" type="module" src="./app.js">builds to the same<meta>and a bare<script type="module">;grep -c nonce dist/index.htmlis 1 (the meta only).<img src="./logo.png">of a 200 KB file give a 1,365,583 byteindex.htmlwith fivedata:image/png;base64,occurrences.entry.js.maphassources: ["../pre.js"], esbuild's has["../orig.ts"].bun build ./in.js --outfile=in.jsand--outdir=.both exit 0 and replacein.js; esbuild printsRefusing to overwrite input file "in.js" (use "--allow-overwrite" to allow this).--pass-with-no-tests: no test files -> exit 1 without, 0 with;-t zzzmatching nothing -> exit 1 without, 0 with.bun install --trustwith no package names: exit 0, package.json unchanged.