Using Bun as Package Manager with Isolated Dependencies in OpenCut
OpenCut leverages Bun 1.3.11 as its JavaScript package manager within a Moon-orchestrated monorepo, using per-app package.json files and a centralized bun.lockb to maintain isolated dependency graphs across apps/web, apps/api, and future desktop clients.
OpenCut is a modern video-editing platform built with a Rust core and TypeScript-React frontend. According to the OpenCut source code, the repository adopts Bun as the default package manager to enable fast installations and deterministic builds while maintaining strict dependency isolation between applications through Moon's workspace configuration.
How Bun Is Integrated in OpenCut
The toolchain configuration relies on Moon to enforce consistent Bun versioning and automated installation across Linux, macOS, and Windows environments.
In .moon/toolchains.yml, the repository pins the exact Bun version and enables automatic dependency installation:
# .moon/toolchains.yml
bun:
version: '1.3.11'
installDependencies: true
This configuration ensures that Moon invokes bun install automatically whenever any package.json or the bun.lockb lockfile changes. The root-level bunfig.toml supplements this with global Bun settings, while .moon/workspace.yml defines the monorepo structure by mapping all directories under apps/* as separate projects.
Isolation Mechanics in the Monorepo
Dependency isolation in OpenCut operates through three coordinated mechanisms:
-
Per-App Manifests: Each application owns its dependencies in isolated
package.jsonfiles located atapps/web/package.jsonandapps/api/package.json. A dependency added to the web app never bleeds into the API unless both manifests explicitly request it. -
Unified Lockfile with Project Boundaries: Running
bun installat the repository root generates a singlebun.lockbfile that contains resolved hashes for every dependency across all apps. Despite the central lockfile, Bun respects the boundaries defined in each manifest, ensuring thatapps/webandapps/apimaintain distinct dependency graphs. -
Moon's Watch Integration: With
installDependencies: trueenabled in.moon/toolchains.yml, Moon monitors changes to any workspacepackage.json. When a developer modifies a dependency list, Moon automatically re-runsbun install, keeping each app's isolated set synchronized without manual intervention.
Development Workflow Examples
Setting up the development environment requires initializing the toolchain and installing dependencies through Bun.
First, install the required toolchain versions using proto:
proto use
This command pulls Bun 1.3.11 and Moon as defined in .prototools. Next, generate the lockfile and install all dependencies:
bun install
To run specific applications in development mode, use Moon's task runner:
# Start the web frontend
moon run web:dev # → http://localhost:5173
# Start the API server
moon run api:dev # → http://localhost:8787
Moon executes these commands within the context of each app's isolated dependency graph, ensuring that apps/web uses its specific React and Tailwind versions while apps/api relies on its server-side packages.
Managing Dependencies in Isolated Apps
Adding packages to a single app without polluting the workspace requires targeting the specific project directory.
To add a dependency only to the web application:
cd apps/web
bun add some-lib@^2.0
This updates apps/web/package.json exclusively. Moon detects the manifest change on the next moon run web:dev invocation and automatically reinstalls dependencies.
For updates that must propagate across multiple apps, use the workspace flag:
bun add zod@^4.4.3 -w
The -w flag applies the version bump to all package.json files in the workspace that already reference the package, preserving isolation for unrelated dependencies.
CI/CD and Cross-Platform Validation
The GitHub Actions workflow in .github/workflows/bun-ci.yml validates the isolated dependency setup by executing moon ci. This command runs the full test suite across Linux, macOS, and Windows runners, using Bun for both installation and execution. The single bun.lockb file guarantees deterministic builds across all platforms, preventing "works on my machine" inconsistencies.
Summary
- Bun 1.3.11 serves as the dedicated package manager in OpenCut's Moon-based monorepo, configured in
.moon/toolchains.yml. - Isolated dependencies are achieved through per-app
package.jsonfiles underapps/combined with Bun's project-aware resolution within a unifiedbun.lockb. - Automated synchronization occurs via Moon's
installDependencies: truesetting, which triggersbun installwhenever any manifest changes. - Development workflow uses
proto useandbun installfor setup, followed bymoon run <app>:devto execute tasks within isolated contexts. - Cross-platform determinism is enforced in CI through the centralized lockfile and Bun's native bundler.
Frequently Asked Questions
How does OpenCut maintain dependency isolation with a single lockfile?
OpenCut uses per-application package.json files located in apps/web/ and apps/api/ to define discrete dependency boundaries. While bun install generates a single bun.lockb at the repository root, Bun respects each manifest's scope, ensuring that packages installed for the web UI remain unavailable to the API server unless explicitly shared. Moon's workspace configuration in .moon/workspace.yml reinforces these boundaries by treating each apps/* directory as an independent project.
What triggers automatic dependency installation in OpenCut?
The .moon/toolchains.yml file enables installDependencies: true, which configures Moon to watch all package.json files within the workspace. When any dependency list changes, Moon automatically invokes bun install before executing subsequent tasks. This eliminates manual steps and ensures that each app's isolated dependency set remains current during development.
Why does OpenCut use Bun instead of npm or pnpm?
According to the OpenCut source code, Bun provides installation speeds approximately 2–3× faster than npm or pnpm through its native bundler and optimized resolver. Additionally, Bun's single-lockfile approach combined with workspace-aware resolution simplifies the monorepo structure while maintaining the strict isolation required between the React frontend (apps/web) and the API backend (apps/api).
How do I add a development dependency to only the web application?
Navigate to the target application directory and use bun add with the development flag:
cd apps/web
bun add -d tailwindcss@^4.1
This command updates only apps/web/package.json. Moon detects the modification during the next task execution and automatically reinstalls dependencies, keeping the change isolated from apps/api and other workspace projects.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →