Plate 61
Bun 1.4.2: Elysia build collision, AsyncLocalStorage leak, CMYK JPEGs (5 Sep 2026)
Bun published 1.4.2 on 5 September 2026: Elysia/bun-build variable collision, AsyncLocalStorage leak under exit()/run(), worker_threads online ordering for @discordjs/ws, and CMYK/YCCK JPEG decode in Bun.Image. Upgrade checklist only; no affiliate.
Aditya Challa4 min read
On this page
- Why 1.4.2 now
- What 1.4.2 changes
- Fixed: `bun build` variable name collision (Elysia)
- Fixed: AsyncLocalStorage memory leak
- Fixed: `worker_threads` `'online'` event order
- Fixed: `Bun.Image` decodes CMYK and YCCK JPEGs
- Upgraded JavaScriptCore
- Other bugfixes called out
- Upgrade checklist
- Bottom line
- Sources
- Related
Bun 1.4.2: Elysia build collision, AsyncLocalStorage leak, CMYK JPEGs (5 Sep 2026)
No affiliate links. This is a frontend runtime note from the Bun v1.4.2 blog, the GitHub release tag, and the npm bun registry. ShopperCove has not run bun upgrade on a production host for this article.
Why 1.4.2 now
npm bun@1.4.2 is the latest dist-tag as of 5 Oct 2026, published 5 Sep 2026 (06:01 UTC / 11:31 IST). The Bun blog post landed the same day (Dylan Conway). Among Prettier (3.9.9, 23 Sep), Rspack (2.2.8, 28 Sep — already packaged), Vite 8.3.2, and Turborepo 2.11.7, this is the open Bun stable pin for the Bun/Prettier/oxc frontend slot.
1.4.2 is a tight patch on the 1.4 line (1.4.0 announced 20 Aug 2026; 1.4.1 on 4 Sep 2026). The operator story is Elysia/bun build correctness, an AsyncLocalStorage memory leak, worker_threads online ordering for @discordjs/ws, and CMYK/YCCK JPEG decode in Bun.Image—plus a JavaScriptCore pull of ~350 WebKit commits. Not a new major.
What 1.4.2 changes
From the Bun v1.4.2 blog:
Fixed: bun build variable name collision (Elysia)
A 1.4.1 regression renamed a nested var to the same name as a let in the same block. Builds importing Elysia failed to load with SyntaxError: Cannot declare a var variable that shadows a let/const/class variable. Fixed, with a regression test. The same bug could also give a let the name of a function parameter or catch binding, producing code that evaluates but computes incorrect values.
Fixed: AsyncLocalStorage memory leak
A 1.4.1 regression: a timer, immediate, or pending promise created inside store.exit() or a nested store.run() kept the outer store value alive for as long as that timer/promise existed. getStore() still returned the correct value—only memory usage grew. Fixed in 1.4.2.
Fixed: worker_threads 'online' event order
A Worker from node:worker_threads did not emit 'online' first, causing @discordjs/ws to hang waiting on a worker's first message. Ordering now matches Node.js.
Fixed: Bun.Image decodes CMYK and YCCK JPEGs
Bun.Image now decodes 4-component CMYK and YCCK JPEGs (previously Image: decode failed). They convert to RGB on decode so transforms and output formats work.
Upgraded JavaScriptCore
About 350 more upstream WebKit commits, including:
Intl.PluralRulesbigint selectors (wasTypeError)- TypedArray constructor/
slicecorrectness whenvalueOfmutates orSymbol.speciesoverlaps Intl.DurationFormatstyle: "digital"stray:when minutes is0and hidden- Proxy handler crash after
Object.setPrototypeOf(handler, null)on a hot class-defined handler
Other bugfixes called out
- Rare JIT crash in long-running processes after a prototype used for cached property lookups was GC'd
- musl (Alpine):
Array.prototype.splice/shift/ shrinkingarray.lengthon object arrays could crash on a GC thread or hang during marking .json()onResponse/Blob/Bun.file()/proc.stdoutnow surfaces the realJSON.parseSyntaxErrormessage instead of a generic parse failurebun install/bun addno longer panic withrange end index out of rangeon package-name hash mismatches inbun.lockb/ cached manifests- Linux:
Bun.file().writer()FileSink no longer double-closes a descriptor when epoll registration fails (e.g.fs.epoll.max_user_watchesexhausted)
Upgrade checklist
- Upgrade exactly:
bun upgrade(or install via bun.com/docs / the install script) and confirmbun --versionprints 1.4.2. - If you ship Elysia (or any app that hit the
bun buildshadowingSyntaxErroron 1.4.1): rebuild and smoke-load the output. - If you use AsyncLocalStorage with
store.exit()/ nestedstore.run()plus long-lived timers or promises: watch RSS after upgrade; the leak was silent. - If you use
@discordjs/ws(or other code that awaits Worker'online'before the first message): re-test connect. - If you decode print/CMYK JPEGs through
Bun.Image: re-run those transform paths. - Alpine/musl hosts: prefer 1.4.2 before relying on array mutate + GC under load.
- No urgency invented beyond the named regressions—this is a patch on an already-shipped 1.4 line, not a CVE advisory of its own.
ShopperCove did not change production Bun versions for this article. Prefer bun.com/blog and the GitHub tags over third-party roundups.
Bottom line
Bun 1.4.2 (5 Sep 2026) is the pin to take if you are on 1.4.1 and hit Elysia/bun build shadowing, an ALS leak under exit()/run(), a @discordjs/ws hang, or CMYK JPEG decode failures—plus the bundled JSC correctness pull. No affiliate.
Sources
- https://bun.com/blog/bun-v1.4.2
- https://bun.com/blog/bun-v1.4.1
- https://bun.com/blog/bun-v1.4.0
- https://github.com/oven-sh/bun/releases/tag/bun-v1.4.2
- https://registry.npmjs.org/bun/1.4.2
- https://bun.com/docs
- https://github.com/oven-sh/bun
- https://bun.com/blog
Related
- https://www.shoppercove.com/blog/rspack-2-2-8-resolver-cache-memory-october-2026
- https://www.shoppercove.com/blog/vite-8-3-2-renderbuilturl-bundled-dev-sourcemaps-october-2026
- https://www.shoppercove.com/blog/turborepo-2-11-7-sdkroot-oidc-cache-october-2026
- https://www.shoppercove.com/blog/pnpm-12-9-1-rust-rewrite-wasm-split-october-2026
- https://www.shoppercove.com/blog/nodejs-26-lts-october-2026-schedule-change
- https://www.shoppercove.com/blog/oxlint-1-87-react-suggestions-a11y-fixes-october-2026
- https://www.shoppercove.com/blog/biome-2-5-15-type-inference-nursery-rules-october-2026
- https://www.shoppercove.com/blog/eslint-10-12-release-october-2026
Lab evidence
What I found running this
Sources read 5 Oct 2026 (Asia/Calcutta): bun.com/blog/bun-v1.4.2 (Dylan Conway, 5 Sep 2026) — fixes: bun build var/let name collision breaking Elysia (SyntaxError shadowing); AsyncLocalStorage memory leak when timer/immediate/promise created inside store.exit()/nested store.run() kept outer store alive; worker_threads Worker 'online' event order (hung @discordjs/ws); Bun.Image CMYK/YCCK 4-component JPEG decode→RGB; ~350 upstream WebKit/JSC commits (Intl.PluralRules bigint, TypedArray valueOf/species slice, DurationFormat digital stray colon, Proxy handler prototype crash); rare JIT crash after prototype GC; musl (Alpine) Array splice/shift/length-shrink GC crash/hang; .json() now surfaces JSON.parse SyntaxError; bun install/add range-end panic on name-hash mismatch; Linux FileSink double-close on epoll register fail. npm registry bun latest=1.4.2 time 2026-09-05T06:01:35.854Z; GitHub tag bun-v1.4.2 200. Context: bun-v1.4.1 (4 Sep) and bun-v1.4.0 (20 Aug) posts 200. Freshness vs already-packaged: prettier 3.9.9 (23 Sep), rspack 2.2.8 (28 Sep), vite 8.3.2, turbo 2.11.7 — Bun 1.4.2 still the open Bun slot after Rspack took cont16. Checklist/upgrade note only; ShopperCove did not bun upgrade production runtimes; no affiliate.
Related links
Plate 33
vue-tsc 3.3.12 TS2300 Duplicate $style: Should You Upgrade?
vue-tsc / Vue Language Tools 3.3.12 (2 Oct 2026): ShopperCove reproduced TS2300 "Duplicate identifier $style" on a two-<style module> fixture—absent on 3.3.11. Also: defineModel default-factory typing, untrusted SFC hardening, template .value call fix. Upgrade decision for Vue teams. No affiliate.
5 Oct 2026
Plate 05
oxfmt 0.72: native Markdown formatter, Prettier 3.9.9 parity test, sorted imports in code fences (5 Oct 2026)
oxfmt 0.72.0 (5 Oct 2026) swaps its Prettier-backed Markdown path for the native oxc_formatter_markdown (breaking). ShopperCove formatted 221 Markdown drafts with oxfmt 0.71.0, 0.72.0 and Prettier 3.9.9: byte-identical output, ~2 s vs ~16 ms. Plus opt-in import sorting inside code fences, the documented divergences, ignore-file and LSP fixes. No affiliate links.
5 Oct 2026
Plate 46
Ready Client Sites live demos: 15 prebuiltwebs previews, admin panel, SEO checks (Oct 2026)
New Ready Client Sites angle: ShopperCove fetched all 15 live prebuiltwebs.com demos — client-rendered React SPAs with hash routes, built-in admin/enquiry/upload APIs, placeholder content JSON, no robots.txt/sitemap, soft 404s — and turned it into a pre-purchase SEO and handover checklist. Distinct from the Node.js packs and launch-checklist posts. One disclosed hop. No purchase.
5 Oct 2026