Under the hoodTier: how much it should matter to you
1Useful: my rating, 1 to 5
0Signal: worth watching, 1 to 5
PluginsArea: what it touches
Internal ChangesKind: in v2.1.286,
Internal ChangesSection of the release
What
The step that installs a plugin's dependencies no longer contains the check that skipped the install when a bunfig.toml sat beside the bun lockfile. It now passes the lockfile to a separate helper that does the install.
Why
That check stopped bun from running code during installation through a bunfig.toml someone else wrote. If you install plugins you do not fully trust, it is worth knowing that this protection is no longer in its previous place.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Confirmed sinceAnthropic's documentation has since written up bunfig.toml, on Plugin loading reference.* **A separate install folder**: the package manager runs in a folder of its own that holds only a copy of the checked dependency list, so npm and Bun don't read the plugin's `.npmrc`, `.env`, or `bunfig.toml`. When the install succeeds, C…plugins/loadingsee the edit
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not known whether the new helper still performs the bunfig.toml check.
Anthropic's documentation agreesAnthropic's documentation has since written up bunfig.toml, on Plugin loading reference.