Skip to content

v0.11.0 — yarn (classic + berry) and bun, measured before judged

Choose a tag to compare

@phantomghost2023 phantomghost2023 released this 22 Sep 04:13
· 10 commits to main since this release

Every Node package manager a repo can use

verify: { builtin: yarn } and verify: { builtin: bun } complete the Node set, so a cached install is checkable in 2–5 ms whichever manager wrote it — and each verifier was measured against the real manager before it was allowed a verdict.

  • yarn, both generations. Classic yarn 1 compares the pattern → resolved-URL map in node_modules/.yarn-integrity with yarn.lock and checks that every directory the install claims to have linked is on disk. Berry compares every location in node_modules/.yarn-state.yml with the locators yarn.lock resolves; a resolved package with no location here (optional, platform-specific) is reported, never judged missing. PnP stays unverifiable and says so.
  • bun, both linkers. Reads bun.lock (trailing commas and all); in a hoisted tree the lockfile key path under node_modules is the install, in an isolated one each resolved package has its store directory node_modules/.bun/<name>@<version> — scoped names spelled @scope+name, other-platform/optional entries skipped and counted.
  • The rule, enforced by the command itself. Classic yarn 1 trusts .yarn-integrity and nothing else: measured on a real 1.22.22 clone, deleting node_modules/is-odd left both the integrity file and yarn install --frozen-lockfile saying "Already up-to-date" (0.2 s) with the package still gone — while --check-files re-links it in the same 0.2 s. So a classic repo's discovered prerequisite is yarn install --frozen-lockfile --check-files, and a missing linked directory is a verdict only under a command that repairs it. Berry rejects that flag outright; bun's isolated linker is the third case of the same rule and reports like pnpm.

The damage table (each cell measured):

manager damage does its install repair it? verdict allowed
yarn 1.22.22 rm -rf node_modules/is-odd plain: no ("Already up-to-date") · --check-files/--force: yes (0.2 s) only under the repairing flag
yarn 4.9.0 a .yarn-state.yml location yes (155 ms) yes
bun 1.2 hoisted a top-level package yes (30–42 ms) yes
bun 1.2 isolated node_modules/.bun/<pkg>@<ver> no ("Checked 6 installs across 32 packages (no changes)") reported, not judged

Full details: CHANGELOG · field notes