{"version":"2.1.286","anchor":"plugin-dependency-install-moved-to-a-helper-bunfigtoml-gua","canonical_anchor":"plugin-dependency-install-moved-to-a-helper-bunfigtoml-gua","heading":"Plugin dependency install moves the bunfig.toml check out of its main step","tier":"internal","area":"Plugins","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/plugin-dependency-install-moved-to-a-helper-bunfigtoml-gua","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### Plugin dependency install moves the bunfig.toml check out of its main step\n\nThe main plugin dependency install step no longer checks for a bunfig.toml before running bun, and now hands the install to a helper\n\n**Unclear.** It is not known whether the new helper still performs the bunfig.toml check.\n\n**What**\n\nThe step that installs a plugin's dependencies no longer contains the check that skipped the install when a `bunfig.toml` sat beside the bun lockfile. It now passes the lockfile to a separate helper that does the install.\n\n**Why**\n\nThat check stopped bun from running code during installation through a `bunfig.toml` someone else wrote. If you install plugins you do not fully trust, it is worth knowing that this protection is no longer in its previous place.\n\n- Area: Plugins\n- Names: `bunfig.toml`\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 0\/5"}