Skip to content

Comment on Oven: The Company Behind Bunparent

Comments

1. Will Oven adopt a security policy for Bun? (https://github.com/oven-sh/bun/security)

Yes.

2. What measures is Oven taking to proactively detect and mitigate vulnerabilities? (e.g.: fuzzing, audits, bug bounties)

Fuzzing will begin soon. Regular security audits will happen around the 1.0 release. Bug bounty seems like a good idea, but it's too early today to know when this will start.

3. Will Oven support Zig development to avoid an existential risk in upstream vulnerabilities?

Yes. Oven will donate to Zig Software Foundation.

More broadly - I think about all of this a lot, but until now Bun has been mostly the work of just me. Bun is still very early - there's a lot that's just not implemented yet.

Thanks for answering Jarred, and I appreciate your answers given the early stage you're at. Runtime diversity in Node is quite exciting, and I'm sure you've more interesting challenges ahead than just security.

I look forward to seeing what you can make of it with Oven.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.