
Security News
CVE Volume Surges Past 48,000 in 2025 as WordPress Plugin Ecosystem Drives Growth
CVE disclosures hit a record 48,185 in 2025, driven largely by vulnerabilities in third-party WordPress plugins.
rescript-bun
Advanced tools
Use Bun with ReScript.
Template repo to get up and running quickly: https://github.com/zth/rescript-bun-starter
You need to be on ReScript v12 >=12.0.0-alpha.4.
Install rescript-bun:
npm i rescript-bun@2
Include them in your rescript.json:
{
"dependencies": ["rescript-bun"]
}
rescript-bun is namespaced, so you'll find all modules listed under the main module RescriptBun.
You're strongly encouraged to open RescriptBun globally, to get the best possible developer experience. You do that by adding this to your rescript.json:
{
"bsc-flags": ["-open RescriptBun", "-open RescriptBun.Globals"]
}
Notice
-open RescriptBun.Globals. This will expose all Bun globals. This might be a matter of taste, but I recommend opening it to get the best experience.
This will make all of Bun available to you without needing to dip into the RescriptBun module explicitly.
This lib copies rescript-nodejs for Bun's Node compatible bindings. Shout out to the maintainers of that project!
Here's a few examples of how it looks. More examples (often inspired by https://bun.sh/guides) can be found in the playground/examples directory in this repo.
To write tests using Bun's built in test runner, just open Test and you'll have everything available to you to write your tests:
open Test
describe("Playing around with tests", () => {
test("addition works", () => {
expect(1 + 1)->Expect.toBe(2)
})
})
This will make all of Bun's testing utilities available to you in the global scope.
Here's setting up a simple web server.
let server = Bun.serve({
fetch: async (request, _server) => {
let userName =
request
->Request.headers
->Headers.get("x-user-name")
->Option.getOr("Unknown user")
Response.make(`Hello ${userName}!`, ~options={status: 200})
},
})
let port =
server
->Bun.Server.port
->Int.toString
let hostName = server->Bun.Server.hostname
Console.log(`Server listening on http://${hostName}:${port}!`)
let password = "super-secure-pa$$word"
let bcryptHash = await Bun.Password.hash(
password,
~algorithm=BCryptAlgorithm({
cost: 4, // number between 4-31
}),
)
let isMatch = await Bun.Password.verify(password, ~hash)
let router = Bun.FileSystemRouter.make({
style: NextJs,
dir: "./pages",
origin: "https://mydomain.com",
assetPrefix: "_next/static/",
})
let matches = router->Bun.FileSystemRouter.match("/")
// Rewrite all <div> to <section>
let rewriter = HTMLRewriter.make()->HTMLRewriter.on(
"*",
{
element: element => {
if element.tagName === "div" {
element.tagName = "section"
}
},
},
)
let response = await fetch("https://bun.sh")
let transformedResponse = rewriter->HTMLRewriter.transform(response)
let html = await transformedResponse->Response.text
Console.log(html)
Currently, bindings exist for the most common things. There's still a good amount of bindings missing. Some bindings will be covered as we go along, while others won't be added.
rescript-webapi instead of rolling our own bindings. I've intentionally not reused any other existing library because I wanted to start from scratch and follow ReScript v11+ idioms as much as possible. But once all of this settles, we need to figure out and share the common denominator with rescript-webapi and other similar projects to this.Contributions are very welcome. We're aiming to cover close to 100% of the Bun API surface, which is quite huge task. But, it's definitively possible and the initial large effort pays dividends over time.
If you do want to contribute, please open an issue saying you're starting work on module X. So we don't accidentally double work.
This project uses Changesets to manage versions and changelogs. Run npm run changeset to create a changeset describing your changes. When changes are merged to main, a GitHub Action opens a release PR and merging that will publish a new version.
This will be fleshed out in a short while.
FAQs
Use Bun with ReScript.
We found that rescript-bun demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
CVE disclosures hit a record 48,185 in 2025, driven largely by vulnerabilities in third-party WordPress plugins.

Security News
Socket CEO Feross Aboukhadijeh joins Insecure Agents to discuss CVE remediation and why supply chain attacks require a different security approach.

Security News
Tailwind Labs laid off 75% of its engineering team after revenue dropped 80%, as LLMs redirect traffic away from documentation where developers discover paid products.