ShopperCove
Menu
All writingBlogTopicsCategoriesAboutRSS
Blog
Categories
Observability & SRE62All categories
About

Plate 61

  1. Blog

Bun 1.4.2: Elysia build collision, AsyncLocalStorage leak, CMYK JPEGs (5 Sep 2026)

Bun published 1.4.2 on 5 September 2026: Elysia/bun-build variable collision, AsyncLocalStorage leak under exit()/run(), worker_threads online ordering for @discordjs/ws, and CMYK/YCCK JPEG decode in Bun.Image. Upgrade checklist only; no affiliate.

Aditya Challa·5 October 2026·4 min read

Summary
On this page
  1. Why 1.4.2 now
  2. What 1.4.2 changes
  3. Fixed: `bun build` variable name collision (Elysia)
  4. Fixed: AsyncLocalStorage memory leak
  5. Fixed: `worker_threads` `'online'` event order
  6. Fixed: `Bun.Image` decodes CMYK and YCCK JPEGs
  7. Upgraded JavaScriptCore
  8. Other bugfixes called out
  9. Upgrade checklist
  10. Bottom line
  11. Sources
  12. Related

Bun 1.4.2: Elysia build collision, AsyncLocalStorage leak, CMYK JPEGs (5 Sep 2026)

No affiliate links. This is a frontend runtime note from the Bun v1.4.2 blog, the GitHub release tag, and the npm bun registry. ShopperCove has not run bun upgrade on a production host for this article.

Why 1.4.2 now

npm bun@1.4.2 is the latest dist-tag as of 5 Oct 2026, published 5 Sep 2026 (06:01 UTC / 11:31 IST). The Bun blog post landed the same day (Dylan Conway). Among Prettier (3.9.9, 23 Sep), Rspack (2.2.8, 28 Sep — already packaged), Vite 8.3.2, and Turborepo 2.11.7, this is the open Bun stable pin for the Bun/Prettier/oxc frontend slot.

1.4.2 is a tight patch on the 1.4 line (1.4.0 announced 20 Aug 2026; 1.4.1 on 4 Sep 2026). The operator story is Elysia/bun build correctness, an AsyncLocalStorage memory leak, worker_threads online ordering for @discordjs/ws, and CMYK/YCCK JPEG decode in Bun.Image—plus a JavaScriptCore pull of ~350 WebKit commits. Not a new major.

What 1.4.2 changes

From the Bun v1.4.2 blog:

Fixed: bun build variable name collision (Elysia)

A 1.4.1 regression renamed a nested var to the same name as a let in the same block. Builds importing Elysia failed to load with SyntaxError: Cannot declare a var variable that shadows a let/const/class variable. Fixed, with a regression test. The same bug could also give a let the name of a function parameter or catch binding, producing code that evaluates but computes incorrect values.

Fixed: AsyncLocalStorage memory leak

A 1.4.1 regression: a timer, immediate, or pending promise created inside store.exit() or a nested store.run() kept the outer store value alive for as long as that timer/promise existed. getStore() still returned the correct value—only memory usage grew. Fixed in 1.4.2.

Fixed: worker_threads 'online' event order

A Worker from node:worker_threads did not emit 'online' first, causing @discordjs/ws to hang waiting on a worker's first message. Ordering now matches Node.js.

Fixed: Bun.Image decodes CMYK and YCCK JPEGs

Bun.Image now decodes 4-component CMYK and YCCK JPEGs (previously Image: decode failed). They convert to RGB on decode so transforms and output formats work.

Upgraded JavaScriptCore

About 350 more upstream WebKit commits, including:

  • Intl.PluralRules bigint selectors (was TypeError)
  • TypedArray constructor/slice correctness when valueOf mutates or Symbol.species overlaps
  • Intl.DurationFormat style: "digital" stray : when minutes is 0 and hidden
  • Proxy handler crash after Object.setPrototypeOf(handler, null) on a hot class-defined handler

Other bugfixes called out

  • Rare JIT crash in long-running processes after a prototype used for cached property lookups was GC'd
  • musl (Alpine): Array.prototype.splice / shift / shrinking array.length on object arrays could crash on a GC thread or hang during marking
  • .json() on Response / Blob / Bun.file() / proc.stdout now surfaces the real JSON.parse SyntaxError message instead of a generic parse failure
  • bun install / bun add no longer panic with range end index out of range on package-name hash mismatches in bun.lockb / cached manifests
  • Linux: Bun.file().writer() FileSink no longer double-closes a descriptor when epoll registration fails (e.g. fs.epoll.max_user_watches exhausted)

Upgrade checklist

  1. Upgrade exactly: bun upgrade (or install via bun.com/docs / the install script) and confirm bun --version prints 1.4.2.
  2. If you ship Elysia (or any app that hit the bun build shadowing SyntaxError on 1.4.1): rebuild and smoke-load the output.
  3. If you use AsyncLocalStorage with store.exit() / nested store.run() plus long-lived timers or promises: watch RSS after upgrade; the leak was silent.
  4. If you use @discordjs/ws (or other code that awaits Worker 'online' before the first message): re-test connect.
  5. If you decode print/CMYK JPEGs through Bun.Image: re-run those transform paths.
  6. Alpine/musl hosts: prefer 1.4.2 before relying on array mutate + GC under load.
  7. No urgency invented beyond the named regressions—this is a patch on an already-shipped 1.4 line, not a CVE advisory of its own.

ShopperCove did not change production Bun versions for this article. Prefer bun.com/blog and the GitHub tags over third-party roundups.

Bottom line

Bun 1.4.2 (5 Sep 2026) is the pin to take if you are on 1.4.1 and hit Elysia/bun build shadowing, an ALS leak under exit()/run(), a @discordjs/ws hang, or CMYK JPEG decode failures—plus the bundled JSC correctness pull. No affiliate.

Sources

  • https://bun.com/blog/bun-v1.4.2
  • https://bun.com/blog/bun-v1.4.1
  • https://bun.com/blog/bun-v1.4.0
  • https://github.com/oven-sh/bun/releases/tag/bun-v1.4.2
  • https://registry.npmjs.org/bun/1.4.2
  • https://bun.com/docs
  • https://github.com/oven-sh/bun
  • https://bun.com/blog

Related

  • https://www.shoppercove.com/blog/rspack-2-2-8-resolver-cache-memory-october-2026
  • https://www.shoppercove.com/blog/vite-8-3-2-renderbuilturl-bundled-dev-sourcemaps-october-2026
  • https://www.shoppercove.com/blog/turborepo-2-11-7-sdkroot-oidc-cache-october-2026
  • https://www.shoppercove.com/blog/pnpm-12-9-1-rust-rewrite-wasm-split-october-2026
  • https://www.shoppercove.com/blog/nodejs-26-lts-october-2026-schedule-change
  • https://www.shoppercove.com/blog/oxlint-1-87-react-suggestions-a11y-fixes-october-2026
  • https://www.shoppercove.com/blog/biome-2-5-15-type-inference-nursery-rules-october-2026
  • https://www.shoppercove.com/blog/eslint-10-12-release-october-2026
bunelysiaasynclocalstoragejavascriptcorecmykworker_threads

Lab evidence

What I found running this

Sources read 5 Oct 2026 (Asia/Calcutta): bun.com/blog/bun-v1.4.2 (Dylan Conway, 5 Sep 2026) — fixes: bun build var/let name collision breaking Elysia (SyntaxError shadowing); AsyncLocalStorage memory leak when timer/immediate/promise created inside store.exit()/nested store.run() kept outer store alive; worker_threads Worker 'online' event order (hung @discordjs/ws); Bun.Image CMYK/YCCK 4-component JPEG decode→RGB; ~350 upstream WebKit/JSC commits (Intl.PluralRules bigint, TypedArray valueOf/species slice, DurationFormat digital stray colon, Proxy handler prototype crash); rare JIT crash after prototype GC; musl (Alpine) Array splice/shift/length-shrink GC crash/hang; .json() now surfaces JSON.parse SyntaxError; bun install/add range-end panic on name-hash mismatch; Linux FileSink double-close on epoll register fail. npm registry bun latest=1.4.2 time 2026-09-05T06:01:35.854Z; GitHub tag bun-v1.4.2 200. Context: bun-v1.4.1 (4 Sep) and bun-v1.4.0 (20 Aug) posts 200. Freshness vs already-packaged: prettier 3.9.9 (23 Sep), rspack 2.2.8 (28 Sep), vite 8.3.2, turbo 2.11.7 — Bun 1.4.2 still the open Bun slot after Rspack took cont16. Checklist/upgrade note only; ShopperCove did not bun upgrade production runtimes; no affiliate.

Notes when a lab post goes up

Occasional email for new hands-on reviews. No sequence and no sponsors.

Related links

  • Plate 33

    vue-tsc 3.3.12 TS2300 Duplicate $style: Should You Upgrade?

    vue-tsc / Vue Language Tools 3.3.12 (2 Oct 2026): ShopperCove reproduced TS2300 "Duplicate identifier $style" on a two-<style module> fixture—absent on 3.3.11. Also: defineModel default-factory typing, untrusted SFC hardening, template .value call fix. Upgrade decision for Vue teams. No affiliate.

    5 Oct 2026

  • Plate 05

    oxfmt 0.72: native Markdown formatter, Prettier 3.9.9 parity test, sorted imports in code fences (5 Oct 2026)

    oxfmt 0.72.0 (5 Oct 2026) swaps its Prettier-backed Markdown path for the native oxc_formatter_markdown (breaking). ShopperCove formatted 221 Markdown drafts with oxfmt 0.71.0, 0.72.0 and Prettier 3.9.9: byte-identical output, ~2 s vs ~16 ms. Plus opt-in import sorting inside code fences, the documented divergences, ignore-file and LSP fixes. No affiliate links.

    5 Oct 2026

  • Plate 46

    Ready Client Sites live demos: 15 prebuiltwebs previews, admin panel, SEO checks (Oct 2026)

    New Ready Client Sites angle: ShopperCove fetched all 15 live prebuiltwebs.com demos — client-rendered React SPAs with hash routes, built-in admin/enquiry/upload APIs, placeholder content JSON, no robots.txt/sitemap, soft 404s — and turned it into a pre-purchase SEO and handover checklist. Distinct from the Node.js packs and launch-checklist posts. One disclosed hop. No purchase.

    5 Oct 2026

On this page

  1. Why 1.4.2 now
  2. What 1.4.2 changes
  3. Fixed: `bun build` variable name collision (Elysia)
  4. Fixed: AsyncLocalStorage memory leak
  5. Fixed: `worker_threads` `'online'` event order
  6. Fixed: `Bun.Image` decodes CMYK and YCCK JPEGs
  7. Upgraded JavaScriptCore
  8. Other bugfixes called out
  9. Upgrade checklist
  10. Bottom line
  11. Sources
  12. Related
All writingBlogCategoriesTopicsAboutPrivacyRSS

© 2026 ShopperCove