Highlights
- Crawler API — new
client.crawlerservice for full-page crawling. - Zero-config auth —
new bdclient()now picks up credentials from the Bright Data CLI (brightdata login) if noapiKey/env token is set. - Security fix (CWE-22) — path traversal in file-saving APIs closed, while still supporting legitimate relative subfolders.
- Bun runtime support —
new bdclient()(and real requests) now work under Bun; previously crashed at construction.
New Features
- Crawler API (
client.crawler):crawl()(sync),trigger()/download()(async via snapshots).CrawlJobis an alias ofScrapeJobfor parity with the Python SDK's vocabulary. - CLI-credential auth resolution: API token resolved by precedence —
apiKeyparam →BRIGHTDATA_API_TOKEN/BRIGHTDATA_API_KEYenv → credentials stored bybrightdata login→ actionableAuthenticationError. The resolved source is appended to theUser-Agent((auth=<source>)) for onboarding visibility.
Fixes
- Path traversal (CWE-22) in
saveResults/SnapshotAPI.download: filenames can no longer escape the working directory via../or absolute paths — both are now rejected with a clearValidationError. Legitimate relative subfolders (e.g.filename: 'output/data.json') are still fully supported and actually created, backed by a real filesystem-level containment + symlink-escape check (getAbsAndEnsureDir), not just a blanketpath.basename().result.save()'s long-standing support for explicit absolute destinations is unchanged. - Bun compatibility:
Transportno longer crashes on Bun. Bun's bundledundiciis a bare, largely-inertAgentstub (nocompose(), noclose(), nodispatch()) and itsrequest()/stream()ignore thedispatcheroption entirely, routing through Bun's own native HTTP client instead. The SDK now capability-detects this instead of calling those methods unconditionally. Practical effect: requests succeed under Bun, but Transport's tuning (connection pooling, timeouts, automatic retry, DNS caching) has no effect there — Bun's own defaults apply. - nodenext / node16 type resolution: explicit
.jsextensions added to all relative import/export specifiers undersrc/, so the shipped.d.tsresolve correctly for consumers onmoduleResolution: "node16"/"nodenext"(previously TS2834 / silentany). A build-time smoke test now loads all 4 published entry points in both ESM and CJS from the actualdist/output. - Snapshot polling: accepts any non-empty status string instead of a closed enum, so new lifecycle values from the API (e.g.
starting,collecting) no longer throw mid-poll.cancelledis now also treated as a terminal status. discover()ergonomics,dataFormat/env aliases, and aTransportlistener leak fix (sharedbeforeExitlistener instead of one per instance — fixesMaxListenersExceededWarningwhen an app creates many clients).
Docs
- Troubleshooting section and geo-targeting notes.
- Crawl API usage in the README.
Internal
SnapshotStatusis now an open union (KnownSnapshotStatus | (string & {})) instead of a barestring, keeping editor autocomplete for known lifecycle values while still accepting values the API may add later.- Removed the one-time
add-js-extensionscodemod script (already did its job, not wired into build/test/CI).
Full Changelog: v1.1.0...v1.2.0