# Using Bun as Package Manager with Isolated Dependencies in OpenCut

> Learn how OpenCut uses Bun as its package manager for isolated dependencies within its monorepo. Discover efficient dependency management with Bun and Moon.

- Repository: [OpenCut.app/OpenCut](https://github.com/OpenCut-app/OpenCut)
- Tags: how-to-guide
- Published: 2026-06-23

---

**OpenCut leverages Bun 1.3.11 as its JavaScript package manager within a Moon-orchestrated monorepo, using per-app [`package.json`](https://github.com/OpenCut-app/OpenCut/blob/main/package.json) files and a centralized `bun.lockb` to maintain isolated dependency graphs across `apps/web`, `apps/api`, and future desktop clients.**

OpenCut is a modern video-editing platform built with a Rust core and TypeScript-React frontend. According to the OpenCut source code, the repository adopts Bun as the default package manager to enable fast installations and deterministic builds while maintaining strict dependency isolation between applications through Moon's workspace configuration.

## How Bun Is Integrated in OpenCut

The toolchain configuration relies on Moon to enforce consistent Bun versioning and automated installation across Linux, macOS, and Windows environments.

In [`.moon/toolchains.yml`](https://github.com/OpenCut-app/OpenCut/blob/main/.moon/toolchains.yml), the repository pins the exact Bun version and enables automatic dependency installation:

```yaml

# .moon/toolchains.yml

bun:
  version: '1.3.11'
  installDependencies: true

```

This configuration ensures that Moon invokes `bun install` automatically whenever any [`package.json`](https://github.com/OpenCut-app/OpenCut/blob/main/package.json) or the `bun.lockb` lockfile changes. The root-level [`bunfig.toml`](https://github.com/OpenCut-app/OpenCut/blob/main/bunfig.toml) supplements this with global Bun settings, while [`.moon/workspace.yml`](https://github.com/OpenCut-app/OpenCut/blob/main/.moon/workspace.yml) defines the monorepo structure by mapping all directories under `apps/*` as separate projects.

## Isolation Mechanics in the Monorepo

Dependency isolation in OpenCut operates through three coordinated mechanisms:

- **Per-App Manifests**: Each application owns its dependencies in isolated [`package.json`](https://github.com/OpenCut-app/OpenCut/blob/main/package.json) files located at [`apps/web/package.json`](https://github.com/OpenCut-app/OpenCut/blob/main/apps/web/package.json) and [`apps/api/package.json`](https://github.com/OpenCut-app/OpenCut/blob/main/apps/api/package.json). A dependency added to the web app never bleeds into the API unless both manifests explicitly request it.

- **Unified Lockfile with Project Boundaries**: Running `bun install` at the repository root generates a single `bun.lockb` file that contains resolved hashes for every dependency across all apps. Despite the central lockfile, Bun respects the boundaries defined in each manifest, ensuring that `apps/web` and `apps/api` maintain distinct dependency graphs.

- **Moon's Watch Integration**: With `installDependencies: true` enabled in [`.moon/toolchains.yml`](https://github.com/OpenCut-app/OpenCut/blob/main/.moon/toolchains.yml), Moon monitors changes to any workspace [`package.json`](https://github.com/OpenCut-app/OpenCut/blob/main/package.json). When a developer modifies a dependency list, Moon automatically re-runs `bun install`, keeping each app's isolated set synchronized without manual intervention.

## Development Workflow Examples

Setting up the development environment requires initializing the toolchain and installing dependencies through Bun.

First, install the required toolchain versions using `proto`:

```bash
proto use

```

This command pulls Bun 1.3.11 and Moon as defined in `.prototools`. Next, generate the lockfile and install all dependencies:

```bash
bun install

```

To run specific applications in development mode, use Moon's task runner:

```bash

# Start the web frontend

moon run web:dev  # → http://localhost:5173

# Start the API server

moon run api:dev  # → http://localhost:8787

```

Moon executes these commands within the context of each app's isolated dependency graph, ensuring that `apps/web` uses its specific React and Tailwind versions while `apps/api` relies on its server-side packages.

## Managing Dependencies in Isolated Apps

Adding packages to a single app without polluting the workspace requires targeting the specific project directory.

To add a dependency only to the web application:

```bash
cd apps/web
bun add some-lib@^2.0

```

This updates [`apps/web/package.json`](https://github.com/OpenCut-app/OpenCut/blob/main/apps/web/package.json) exclusively. Moon detects the manifest change on the next `moon run web:dev` invocation and automatically reinstalls dependencies.

For updates that must propagate across multiple apps, use the workspace flag:

```bash
bun add zod@^4.4.3 -w

```

The `-w` flag applies the version bump to all [`package.json`](https://github.com/OpenCut-app/OpenCut/blob/main/package.json) files in the workspace that already reference the package, preserving isolation for unrelated dependencies.

## CI/CD and Cross-Platform Validation

The GitHub Actions workflow in [`.github/workflows/bun-ci.yml`](https://github.com/OpenCut-app/OpenCut/blob/main/.github/workflows/bun-ci.yml) validates the isolated dependency setup by executing `moon ci`. This command runs the full test suite across Linux, macOS, and Windows runners, using Bun for both installation and execution. The single `bun.lockb` file guarantees deterministic builds across all platforms, preventing "works on my machine" inconsistencies.

## Summary

- **Bun 1.3.11** serves as the dedicated package manager in OpenCut's Moon-based monorepo, configured in [`.moon/toolchains.yml`](https://github.com/OpenCut-app/OpenCut/blob/main/.moon/toolchains.yml).
- **Isolated dependencies** are achieved through per-app [`package.json`](https://github.com/OpenCut-app/OpenCut/blob/main/package.json) files under `apps/` combined with Bun's project-aware resolution within a unified `bun.lockb`.
- **Automated synchronization** occurs via Moon's `installDependencies: true` setting, which triggers `bun install` whenever any manifest changes.
- **Development workflow** uses `proto use` and `bun install` for setup, followed by `moon run <app>:dev` to execute tasks within isolated contexts.
- **Cross-platform determinism** is enforced in CI through the centralized lockfile and Bun's native bundler.

## Frequently Asked Questions

### How does OpenCut maintain dependency isolation with a single lockfile?

OpenCut uses per-application [`package.json`](https://github.com/OpenCut-app/OpenCut/blob/main/package.json) files located in `apps/web/` and `apps/api/` to define discrete dependency boundaries. While `bun install` generates a single `bun.lockb` at the repository root, Bun respects each manifest's scope, ensuring that packages installed for the web UI remain unavailable to the API server unless explicitly shared. Moon's workspace configuration in [`.moon/workspace.yml`](https://github.com/OpenCut-app/OpenCut/blob/main/.moon/workspace.yml) reinforces these boundaries by treating each `apps/*` directory as an independent project.

### What triggers automatic dependency installation in OpenCut?

The [`.moon/toolchains.yml`](https://github.com/OpenCut-app/OpenCut/blob/main/.moon/toolchains.yml) file enables `installDependencies: true`, which configures Moon to watch all [`package.json`](https://github.com/OpenCut-app/OpenCut/blob/main/package.json) files within the workspace. When any dependency list changes, Moon automatically invokes `bun install` before executing subsequent tasks. This eliminates manual steps and ensures that each app's isolated dependency set remains current during development.

### Why does OpenCut use Bun instead of npm or pnpm?

According to the OpenCut source code, Bun provides installation speeds approximately 2–3× faster than npm or pnpm through its native bundler and optimized resolver. Additionally, Bun's single-lockfile approach combined with workspace-aware resolution simplifies the monorepo structure while maintaining the strict isolation required between the React frontend (`apps/web`) and the API backend (`apps/api`).

### How do I add a development dependency to only the web application?

Navigate to the target application directory and use `bun add` with the development flag:

```bash
cd apps/web
bun add -d tailwindcss@^4.1

```

This command updates only [`apps/web/package.json`](https://github.com/OpenCut-app/OpenCut/blob/main/apps/web/package.json). Moon detects the modification during the next task execution and automatically reinstalls dependencies, keeping the change isolated from `apps/api` and other workspace projects.