bun publish
Use bun publish to publish a package to the npm registry
bun publish packs your package into a tarball, strips catalog and workspace protocols from the package.json (resolving versions if necessary), and publishes to the registry specified in your configuration files. Both bunfig.toml and .npmrc files are supported.
## Publishing the package from the current working directory
bun publishbun publish v1.3.3 (ca7428e9)
packed 203B package.json
packed 224B README.md
packed 30B index.ts
packed 0.64KB tsconfig.json
Total files: 4
Shasum: 79e2b4377b63f4de38dc7ea6e5e9dbee08311a69
Integrity: sha512-6QSNlDdSwyG/+[...]X6wXHriDWr6fA==
Unpacked size: 1.1KB
Packed size: 0.76KB
Tag: latest
Access: default
Registry: http://localhost:4873/
+ publish-1@1.0.0To pack and publish separately, run bun pm pack, then bun publish with the path to the output tarball.
bun pm pack
...
bun publish ./package.tgzbun publish does not run lifecycle scripts (prepublishOnly/prepack/prepare/postpack/publish/postpublish) if a
tarball path is provided. Scripts run only when bun publish packs the package itself.
--access
--access sets the access level of the package being published, either public or restricted. Unscoped packages are always public, and publishing an unscoped package with --access restricted is an error.
bun publish --access public--access can also be set in the publishConfig field of your package.json.
{
"publishConfig": {
"access": "restricted"
}
}--tag
Set the tag of the package version being published. By default, the tag is latest. The initial version of a package is always given the latest tag in addition to the specified tag.
bun publish --tag alpha--tag can also be set in the publishConfig field of your package.json.
{
"publishConfig": {
"tag": "next"
}
}--dry-run
--dry-run runs the publish process without publishing the package, so you can verify what would be published.
bun publish --dry-run--tolerate-republish
Exit with code 0 instead of 1 if the package version already exists. Useful in CI/CD where jobs may be re-run.
bun publish --tolerate-republish--gzip-level
Set the gzip compression level used when packing the package, from 0 to 9 (default 9). Only applies to bun publish without a tarball path argument.
--auth-type
If you have 2FA enabled for your npm account, bun publish prompts you for a one-time password, either through a browser or in the CLI. --auth-type tells the npm registry which method you prefer: web (the default) or legacy.
bun publish --auth-type legacy
...
This operation requires a one-time password.
Enter OTP: 123456
...--otp
Provide a one-time password directly to the CLI. If the password is valid, bun publish skips the extra one-time password prompt before publishing:
bun publish --otp 123456bun publish respects the NPM_CONFIG_TOKEN environment variable, useful when publishing from GitHub Actions or
other automated workflows.
CLI Usage
bun publish distPublishing Options
--accessstringSet the access level of the package being published, either public or restricted. Unscoped packages are always public; publishing an unscoped package with --access restricted is an error.
bun publish --access public--access can also be set in the publishConfig field of your package.json.
{
"publishConfig": {
"access": "restricted"
}
}--tagstringdefault: latestSet the tag of the package version being published. By default, the tag is latest. The initial version of a package is always given the latest tag in addition to the specified tag.
bun publish --tag alpha--tag can also be set in the publishConfig field of your package.json.
{
"publishConfig": {
"tag": "next"
}
}--dry-runbooleanSimulate the publish process without publishing the package, to verify its contents first.
bun publish --dry-run--gzip-levelstringdefault: 9Specify the level of gzip compression to use when packing the package. Only applies to bun publish without a tarball
path argument. Values range from 0 to 9 (default is 9).
--auth-typestringdefault: webIf you have 2FA enabled for your npm account, bun publish prompts you for a one-time password, either through a browser or the CLI. --auth-type tells the npm registry which method you prefer: web (the default) or legacy.
bun publish --auth-type legacy
...
This operation requires a one-time password.
Enter OTP: 123456
...--otpstringProvide a one-time password directly to the CLI. A valid password skips the extra one-time password prompt before publishing.
bun publish --otp 123456bun publish respects the NPM_CONFIG_TOKEN environment variable, so you can publish from GitHub Actions or other
automated workflows.
Registry Configuration
Custom Registry
--registrystringSpecify registry URL, overriding .npmrc and bunfig.toml
bun publish --registry https://my-private-registry.comSSL Certificates
--castringProvide Certificate Authority signing certificate
--cafilestringPath to Certificate Authority certificate file
bun publish --ca "-----BEGIN CERTIFICATE-----..."Publishing Options
Dependency Management
-p, --productionbooleanDon’t install devDependencies
--omitstringExclude dependency types: dev, optional, or peer
-f, --forcebooleanAlways request the latest versions from the registry & reinstall all dependencies
Script Control
--ignore-scriptsbooleanSkip lifecycle scripts during packing and publishing
--trustbooleanAdd packages to trustedDependencies and run their scripts
Lifecycle Scripts — When you publish a pre-built tarball, Bun does not run lifecycle scripts such as
prepublishOnly and prepack; they only run when Bun packs the package itself.
File Management
--no-savebooleanDon’t update package.json or lockfile
--frozen-lockfilebooleanDisallow changes to lockfile
--yarnbooleanGenerate yarn.lock file (yarn v1 compatible)
Performance
--backendstringPlatform optimizations: clonefile (default), hardlink, symlink, or copyfile
--network-concurrencynumberdefault: 48Maximum concurrent network requests
--concurrent-scriptsnumberMaximum concurrent lifecycle scripts (default: 2x CPU cores)
Output Control
--silentbooleanSuppress all output
--verbosebooleanShow detailed logging
--no-progressbooleanHide progress bar
--no-summarybooleanDon’t print publish summary