Bun 1.4.3
Bun v1.4.3 landed on October 10, 2026, and the headline is not one feature but one big number: 166 issues fixed, 122 of them carrying a thumbs-up from the community.
🐹 Check Mate: bun check Arrives
The marquee addition is bun check, a TypeScript type checker built directly into the runtime. Bun reports it runs 3x to 6.4x faster than tsc 7. You can also bolt it onto existing commands: bun run --check, bun test --check, and bun build --check each run type checking as part of the normal workflow, which means far fewer separate terminal tabs.
⚡ Performance Push
- 67 to 89 percent less idle CPU while your server sits idle, which shows up directly in cloud bills for long-running services.
- Up to 2.7x faster large responses through
node:http. - Faster JSON.parse and faster handling of many rejected promises, courtesy of a JavaScriptCore upgrade.
- Faster startup for
--compile --bytecodeexecutables, plus profile-guided bytecode layout forbun build --compile.
🧰 New Toys in the Runtime
Bun.FetchSession keeps connection pools, cookies, and caches alive across requests so repeated calls reuse the same session instead of rebuilding state. An experimental Bun.ModuleGraph exposes the module graph to code, with a dispose() method that closes its servers, sockets, timers, and child processes. CompressionStream now accepts a compression level, Bun.serve supports If-Range headers for conditional range requests, and fetch() handles proxy environment variables more accurately.
🔒 Security Setting
A new --disallow-code-generation-from-strings flag blocks eval() and new Function(). Any attempt to build code from a string raises an EvalError, which is a useful hardening switch for services that never need dynamic evaluation.
📦 Bundler and Installer Bits
bun installnow skips tarballs it will not install, cutting wasted downloads and disk churn.bun builduses noticeably less memory when many entry points are declared.Bun.buildsupports[hashN]in output names, and the metafile now names the input file behind a split dynamicimport().
🐛 Bug Bashes
Beyond the headline items, the release repairs security issues and dozens of Node.js compatibility gaps across the runtime, transpiler, bundler, minifier, CSS parser, test runner, Bun Shell, SQL, SQLite and S3 clients, TypeScript types, and Windows. Eight contributors signed off on the build.
⬆️ Upgrade
Run bun upgrade, or install fresh with curl -fsSL https://bun.sh/install | bash. Windows users can use powershell -c "irm bun.sh/install.ps1|iex", and npm users can still reach it through npm install -g bun. Full notes live at bun.com/blog/bun-v1.4.3. Upgrade when you can, but do not delay: the idle CPU savings alone pay for the few minutes it takes.