Agent skill

Bun Workspaces

by shepherdjerred in shepherdjerred/monorepo

Current Bun workspace guidance for isolated and hoisted linkers, catalogs, filters, scripts, dependency classes, lockfiles, lifecycle trust, caches, publishing, TypeScript package exports, and…

GPL-3.0Auto-check passedDevelopment

Install Bun Workspaces

skills CLI
$ npx skills add shepherdjerred/monorepo --skill bun-workspaces -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install shepherdjerred/monorepo bun-workspaces --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/shepherdjerred/monorepo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/dotfiles/dot_agents/skills/bun-workspaces .claude/skills/bun-workspaces && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bun-workspaces
GitHub stars
112
Token cost
~2.2k tokens
SKILL.md length
947 words
Files
4 (incl. references)
Skills in repo
63
Repo updated
First seen
Licence
GPL-3.0

At a glance

Current Bun workspace guidance for isolated and hoisted linkers, catalogs, filters, scripts, dependency classes, lockfiles, lifecycle trust, caches, publishing, TypeScript package exports, and…

  • Reviewing a Bun monorepo
  • SKILL.md covers Current baseline, Workspace declaration, Linker selection and Cache versus global store, plus 9 more sections
  • Calls bun and bunx
  • Tasks that involve Dependency management

What it does

Bun Workspaces is an agent skill from shepherdjerred/monorepo. Current Bun workspace guidance for isolated and hoisted linkers, catalogs, filters, scripts, dependency classes, lockfiles, lifecycle trust, caches, publishing, TypeScript package exports, and containers. Use when configuring or reviewing a Bun monorepo.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/linkers-dependencies-and-lockfiles.md`, `references/releases.md` and `references/scripts-builds-and-publishing.md`).

It sits in Development, covering Dependency management and Monorepo tooling. It works with TypeScript. The repository describes itself as: Monorepo for all of my projects. The licence is GPL-3.0.

When your agent uses it

  • Reviewing a Bun monorepo
  • Tasks that involve Dependency management
  • Tasks that involve Monorepo tooling

Example prompts

  • “/bun-workspaces”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit da14ae9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun
    • bunx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use bunx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bun Workspaces loads about 2.2k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 947 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from shepherdjerred/monorepo at commit da14ae9, republished under its GPL-3.0 licence (© shepherdjerred). 947 words, ~2,208 tokens.

Download SKILL.mdSave it as .claude/skills/bun-workspaces/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
bun-workspaces
description
Current Bun workspace guidance for isolated and hoisted linkers, catalogs, filters, scripts, dependency classes, lockfiles, lifecycle trust, caches, publishing, TypeScript package exports, and containers. Use when configuring or reviewing a Bun monorepo.

Bun Workspaces

Use one root workspace and lockfile, resolve internal packages through workspace:* links and package exports, and choose script scheduling from dependency order and task lifetime. Do not hide packaging errors with TypeScript source aliases.

Current baseline

Verified against Bun 1.3.14 on 2026-08-03:

bash
bun --version

New workspace projects with lockfile configVersion = 1 default to the isolated linker. Existing and migrated projects preserve historical linker choices. Bun 1.3.14 adds an experimental isolated-linker global virtual store that is off by default.

Read references/releases.md for the 49-page research ledger. Read references/linkers-dependencies-and-lockfiles.md for linker, store, catalogs, dependency classes, lifecycle trust, and migration. Read references/scripts-builds-and-publishing.md for filters, scheduling, package exports, TypeScript, CI, containers, audit, pack, and publish.

Workspace declaration

The root owns the workspace patterns and shared lockfile:

json
{
  "private": true,
  "workspaces": {
    "packages": ["packages/*"],
    "catalog": {
      "typescript": "^7.0.0"
    },
    "catalogs": {
      "testing": {
        "@types/bun": "latest"
      }
    }
  }
}

catalog: resolves the singular default catalog. A named catalog entry uses catalog:name. Do not put a named default group under catalogs and reference it as bare catalog:.

Internal package dependency:

json
{
  "dependencies": {
    "@example/shared": "workspace:*"
  }
}

Bun rewrites workspace and catalog protocols appropriately during publication.

Linker selection

ProjectDefault/behavior
New workspace with current lockfile configIsolated linker
New single-package projectHoisted linker
Existing/pre-1.3.2 projectPreserves historical hoisted behavior unless changed
npm/yarn migrationPreserves hoisted model
pnpm migrationUses isolated model

Set the linker explicitly when deterministic strictness is required:

toml
[install]
linker = "isolated"

Isolated installs prevent phantom dependencies and create peer-set-specific package identities. Test tools and bundlers against the real layout; do not depend on accidental hoisting.

Cache versus global store

The global cache at ~/.bun/install/cache stores fetched package content and metadata. The experimental global virtual store is different: it is isolated-linker-only, disabled by default, and symlinks projects through the cache's links area.

toml
[install]
globalStore = true

Keep this setting machine-local unless the repository has revalidated parallel CI behavior. General upstream race-safety claims do not supersede the repository's known shared-store CI constraint.

Dependencies

Bun installs peer and optional dependencies by default. peerDependenciesMeta.optional means a peer may be absent; it does not force installation.

bash
bun add --cwd packages/shared lodash
bun add --cwd packages/plugin --peer react
bun add --cwd packages/tool --optional native-addon

bun add does not have --filter; use --cwd or run from the package directory. Use omit flags only when the install contract intentionally excludes peer/optional packages.

Lockfile and CI

bun.lock is the authoritative text lockfile. Use:

bash
bun ci

bun ci is the concise frozen install. bun install --lockfile-only skips node_modules installation but writes the lockfile and can populate global cache metadata or Git/tarball dependencies.

Yarn v1 lockfile printing creates an interoperability artifact on every install; do not make it a generic default.

For bun.lockb migration, generate and inspect bun.lock, run a clean frozen install and focused verification, then remove the preserved binary source lockfile. Automatic migration occurs only when bun.lock is absent.

Lifecycle trust

Dependency lifecycle scripts are allow-listed. trustedDependencies replaces Bun's built-in trusted list rather than extending it; an empty list trusts none. Non-registry sources require explicit trust.

--ignore-scripts disables project and trusted dependency lifecycle scripts. In bunfig, use ignoreScripts; there is no documented lifecycle = ["postinstall"] policy setting.

Review untrusted scripts before enabling them:

bash
bun pm untrusted
bun pm trust <package>

Script scheduling

Filtered finite scripts honor workspace dependency order; independent packages can overlap. Keep local builds focused:

bash
bunx turbo run build --filter=<workspace>

At this monorepo's root, use bunx turbo run build for repo-wide and focused builds so dependencies run in task-graph order. Never use bun run --filter '*' build here: bypassing the bounded Turbo task graph can launch thousands of processes and exhaust the machine.

Long-running dev servers block dependents under dependency ordering. Start only the intended independent servers. Run each selected workspace in its own terminal, or use the repository's bounded dev orchestrator:

bash
# terminal 1
bun run --filter '<workspace-a>' dev

# terminal 2
bun run --filter '<workspace-b>' dev

Focused execution remains the default during development. Do not apply blanket parallelism to builds whose order matters.

Show full SKILL.md (368 more words)Show less

Updates and overrides

bun update respects current semver ranges by default. For a reviewed workspace selection:

bash
bun update --interactive --recursive

--latest can rewrite ranges across breaking versions and needs migration review.

Overrides/resolutions are top-level only and can affect direct or transitive dependencies. Document the reason and removal condition for every forced version.

TypeScript and package exports

Resolve workspace packages through Bun's node_modules links and each package's exports. TypeScript warns against paths entries that point at monorepo package sources because they bypass real package exports and consumer resolution.

Use project references for compiler graph ordering. Put the types export condition before runtime conditions:

json
{
  "exports": {
    ".": {
      "types": "./dist/index.d.ts",
      "import": "./dist/index.js"
    }
  }
}

Export every documented subpath or import public types from the root. Choose Bun, Node, or browser build targets from supported consumers. TypeScript normally belongs in devDependencies, not peers, unless consumers use a compiler API in the public contract.

Do not add skipLibCheck to conceal workspace declaration errors.

CI and containers

Use current oven-sh/setup-bun@v2 and pin the project's Bun version instead of latest. In Docker, preserve workspace manifest paths; a wildcard copy into one directory flattens manifests and breaks the declared layout.

Prefer a pinned multi-stage image, install against the complete/preserved workspace tree, copy only runtime artifacts, and run as the image's non-root bun user.

Pack, publish, and audit

Inspect package contents before publication:

bash
bun pm pack
bun publish --dry-run --access public
bun audit
bun why <package>

Publishing is an external mutation requiring explicit package, registry, tag/access, artifact, and credentials. Bun strips/resolves workspace and catalog protocols. Publishing a supplied tarball does not run pack/publish lifecycle scripts. There is no implicit monorepo-wide publish command.

bun audit sends installed package/version data to npm and skips non-default registries. Account for that privacy and coverage boundary.

Review checklist

  • Verify Bun 1.3.14 and the lockfile config/linker history.
  • Use isolated installs explicitly when strict dependency boundaries matter.
  • Keep experimental global store machine-local until CI is revalidated.
  • Use singular default catalog and named catalogs correctly.
  • Add dependencies through package --cwd; do not invent add filters.
  • Preserve peer/optional semantics and lifecycle trust policy.
  • Use bun ci and inspect lockfile migration before deleting the old lock.
  • Run finite builds dependency-aware and long-lived servers explicitly parallel.
  • Resolve packages through workspace links/exports, not TypeScript source paths.
  • Preserve workspace directories in Docker and use a non-root runtime stage.
  • Dry-run and inspect package contents before authorized publication.

© shepherdjerred, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in packages/dotfiles/dot_agents/skills/bun-workspaces of shepherdjerred/monorepo.

  • SKILL.md
  • references/linkers-dependencies-and-lockfiles.md
  • references/releases.md
  • references/scripts-builds-and-publishing.md

Open the folder on GitHubat commit da14ae9

Compare with similar skills

Bun Workspaces next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bun Workspaces compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bun Workspaces this skillshepherdjerred/monorepo112—~2.2kAutomated safety check: PassGPL-3.0
Pnpm Engineteambit/bit18k—~1.9kAutomated safety check: PassCustom licence
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Monorepo Tooling and Dependenciespierrecomputer/pierre6.2k—~1.1kAutomated safety check: PassApache-2.0
TypeScript Monorepo Conventionspierrecomputer/pierre6.2k—~450Automated safety check: PassApache-2.0
Repo Maintenance Nodecommercetools/ui-kit154—~3kAutomated safety check: NotesMIT

Similar skills

  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.

    6.2k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • TypeScript Monorepo Conventions

    pierrecomputer/pierre

    Conventions for adding packages and apps to a TypeScript monorepo: project references, moon tasks, workspace dependencies and published package exports.

    6.2k GitHub stars~450 tokensUpdated today
    DevelopmentAuto-check passed
  • Repo Maintenance Node

    commercetools/ui-kit

    Perform a broad Node/TypeScript repository health sweep — formatting, linting, type errors, dead code, dependency hygiene, and open Renovate PRs.

    154 GitHub stars~3k tokensUpdated 4 days ago
    DevelopmentAuto-check: notes
  • Nx Import

    nrwl/nx

    Import, merge, or combine repositories into an Nx workspace using nx import.

    29k GitHub starsUsed in 6 repos~3.5k tokens
    DevelopmentAuto-check passed

More from shepherdjerred/monorepo

All 63 skills in this repo
  • Bun Runtime Best Practices

    shepherdjerred/monorepo

    Bun runtime APIs and current operational patterns for files, processes, modules, networking, databases, tests, and deployment.

    112 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Bun Test Patterns

    shepherdjerred/monorepo

    Current Bun test runner guidance for discovery, isolation, parallelism, sharding, changed tests, mocks, timers, snapshots, coverage, DOM Testing Library, and integration teardown.

    112 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Deep Research

    shepherdjerred/monorepo

    This skill should be used when the user asks to "deep research", "research this topic", "investigate thoroughly", "do a deep dive on", "comprehensive research on", "find everything about", "survey…

    112 GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Figma Use

    shepherdjerred/monorepo

    This skill should be used when the user asks to "create a Figma design", "design in Figma", "make a Figma mockup", "create an app icon", "design UI", "render JSX to Figma", "export from Figma"…

    112 GitHub stars~946 tokensUpdated today
    Auto-check passed
  • Fish Helper

    shepherdjerred/monorepo

    Current Fish shell scripting, functions, abbreviations, completions, variables, events, configuration, plugins, testing, and safety guidance.

    112 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Gh Helper

    shepherdjerred/monorepo

    Complete GitHub operations via gh CLI - repos, issues, PRs, code search, releases, file management When user mentions GitHub, repositories, issues, PRs, gh command, code search, commits, file contents

    112 GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Bun Workspaces

What does Bun Workspaces do?

Current Bun workspace guidance for isolated and hoisted linkers, catalogs, filters, scripts, dependency classes, lockfiles, lifecycle trust, caches, publishing, TypeScript package exports, and…. Bun Workspaces is an agent skill from shepherdjerred/monorepo. Current Bun workspace guidance for isolated and hoisted linkers, catalogs, filters, scripts, dependency classes, lockfiles, lifecycle trust, caches, publishing, TypeScript package exports, and containers.

When should I use Bun Workspaces?

Bun Workspaces fits situations like: reviewing a Bun monorepo; tasks that involve Dependency management; tasks that involve Monorepo tooling.

How do I install Bun Workspaces in Claude Code?

Run `npx skills add shepherdjerred/monorepo --skill bun-workspaces -a claude-code`. Or copy the skill folder (packages/dotfiles/dot_agents/skills/bun-workspaces in shepherdjerred/monorepo) into .claude/skills/bun-workspaces in your project. Claude Code loads it when a task matches its description.

How do I install Bun Workspaces in Codex?

Run `npx skills add shepherdjerred/monorepo --skill bun-workspaces -a codex`. Or copy the skill folder (packages/dotfiles/dot_agents/skills/bun-workspaces in shepherdjerred/monorepo) into .agents/skills/bun-workspaces in your project. Codex loads it when a task matches its description.

Can I use Bun Workspaces in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shepherdjerred/monorepo --skill bun-workspaces -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bun-workspaces, .gemini/skills/bun-workspaces, .github/skills/bun-workspaces and .opencode/skills/bun-workspaces in your project.

What does Bun Workspaces need to run?

Going by SKILL.md and its folder, Bun Workspaces needs the command-line tools its instructions call (bun and bunx). Our summary lists: Docker.

Does Bun Workspaces access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Bun Workspaces safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bun Workspaces use?

Bun Workspaces is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bun Workspaces use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Bun Workspaces?

Skills that share tags, products or a category with Bun Workspaces: Pnpm Engine (teambit/bit, 18k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Monorepo Tooling and Dependencies (pierrecomputer/pierre, 6.2k stars) and TypeScript Monorepo Conventions (pierrecomputer/pierre, 6.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bun Workspaces?

shepherdjerred (a GitHub user) maintains it in shepherdjerred/monorepo, which has 112 GitHub stars. The repository holds 63 skills in this directory. The repository was last updated on October 8, 2026.

Source: shepherdjerred/monorepo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.