diff --git a/docs/bundler/esbuild.mdx b/docs/bundler/esbuild.mdx
index 716ae790bd34..ceef571ce9a7 100644
--- a/docs/bundler/esbuild.mdx
+++ b/docs/bundler/esbuild.mdx
@@ -48,11 +48,11 @@ In Bun's CLI, boolean flags like `--minify` take no argument. Flags that take on
| `--packages` | `--packages` | No differences |
| `--platform` | `--target` | Renamed to `--target` for consistency with tsconfig. Does not support `neutral`. |
| `--serve` | n/a | Not applicable |
-| `--sourcemap` | `--sourcemap` | Supports `linked` (the default when no value is given), `external`, `inline`, and `none`. Does not support esbuild's `both`. |
+| `--sourcemap` | `--sourcemap` | Supports `linked` (the default when no value is given), `external`, `inline`, and `none`. Does not support esbuild's `both`. Bun does not read input sourcemaps (a `//# sourceMappingURL` comment in a source file), so it does not compose them into the output map the way esbuild does. |
| `--splitting` | `--splitting` | No differences |
| `--target` | n/a | Not supported. Bun's bundler performs no syntactic down-leveling. |
-| `--watch` | `--watch` | No differences |
-| `--allow-overwrite` | n/a | Bun never allows overwriting |
+| `--watch` | `--watch` | No differences for bundles. With `--no-bundle`, Bun runs the first build and then keeps the process alive without rebuilding on change, whereas esbuild also watches transform-only builds. |
+| `--allow-overwrite` | n/a | No flag. `bun build` always writes its output files and replaces whatever exists at those paths without a prompt. This includes an output path that is also one of the build's inputs, so keep `--outdir`/`--outfile` away from your source files. |
| `--analyze` | n/a | Not supported |
| `--asset-names` | `--asset-naming` | Renamed for consistency with naming in JS API |
| `--banner` | `--banner` | Only applies to js bundles |
@@ -162,7 +162,7 @@ In Bun's CLI, boolean flags like `--minify` take no argument. Flags that take on
| `reserveProps` | n/a | Not supported |
| `resolveExtensions` | n/a | Not supported |
| `sourceRoot` | n/a | Not supported |
-| `sourcemap` | `sourcemap` | Supports `"none"`, `"linked"`, `"inline"`, and `"external"` |
+| `sourcemap` | `sourcemap` | Supports `"none"`, `"linked"`, `"inline"`, and `"external"`. Bun does not read input sourcemaps in source files or compose them into the output map. |
| `sourcesContent` | n/a | Not supported |
| `splitting` | `splitting` | No differences |
| `stdin` | n/a | Not supported |
diff --git a/docs/bundler/index.mdx b/docs/bundler/index.mdx
index c8a89aed92f6..d2312f099a69 100644
--- a/docs/bundler/index.mdx
+++ b/docs/bundler/index.mdx
@@ -763,6 +763,8 @@ Specifies the type of sourcemap to generate.
The associated `*.js.map` sourcemap is a JSON file containing an equivalent `debugId` property.
+The generated sourcemap maps to the files the bundler read. When an input file is itself generated code with its own `//# sourceMappingURL` comment (inline, or a `.map` file next to it), Bun does not read that input sourcemap. The output map then points at the generated file, not at its original source.
+
### minify
Whether to enable minification. Default `false`.
diff --git a/docs/bundler/standalone-html.mdx b/docs/bundler/standalone-html.mdx
index 6b30f7e69e30..a659751befd0 100644
--- a/docs/bundler/standalone-html.mdx
+++ b/docs/bundler/standalone-html.mdx
@@ -311,4 +311,6 @@ Bun replaces references to `process.env.API_URL` in your JavaScript with the lit
- **Code splitting** is not supported — `--splitting` cannot be used with `--compile --target=browser`
- **Large assets** increase file size since they're base64-encoded (33% overhead vs the raw binary)
+- **Repeated references** to one asset each embed their own copy. A `data:` URI cannot be shared, so Bun stores an image used by two `
` tags, a CSS `url()` and a JS import four times. When size matters, reference a large asset from one place (one CSS class, or one JS import that the rest of the code reuses)
- **External URLs** (CDN links, absolute URLs) stay as-is: Bun inlines only relative paths
+- **Content Security Policy**: the output relies on inline `