← Back to context

Comment by Quothling

3 hours ago

I think Bun is still all the rage in some areas. For us the fact that it makes it easy to work with compliance, means it's often what we pick in place of Node when we work with typescript. Being able to build an API without using anything but the Bun runtime, the Microsoft Azure and our own internal Node packages makes the NIS2 compliance much less of a burden than if we'd work with Node.

That being said. I don't think anyone in my team considers us a "Bun" team in regards to Typescript, all our internal packages are Node packages as an example.

I don't personally have an opinion on it being owned by Anthropic. It was part of our risk assessment, but it obviously passed.

If compliance is the main deciding factor, wouldn't Deno be a major selling point since its inherently NIS2 compliant out of the box? Security is its primary foundational selling point

Bun has the same permissive trust model as Node

curious: given the pace of bun development, lack of LTS/support on older point releases etc, how does it qualify this compliance check assuming I believe you're alluding to fewer deps as the reason for "less burden"?