Who Burned My App? Security Hazards in Bun JavaScript Runtime and How Node.js Compares
June 26, 2025
Intermediate | Authentication and Security | Heb/Eng-TBA

The rising Bun JavaScript runtime is making strides and growing in adoption but what are the looming security risks and insecure code pitfalls youโ€™ll end up in? This is the session to deep dive into the shadow realm often hidden from plain sight: the underlying API surface of the runtime.

Through a comparative outlook of Node.js, weโ€™ll journey into security vulnerabilities from supply chain threats to and onto command injection, and prototype pollution and how they fare in Bun. What are Bunโ€™s greatest security strengths? Youโ€™ll learn those too. This is a unique chance to gain first-hand insights to security weaknesses in both Node.js and Bun runtime and explore the unique threat models, security posture and the security pitfalls and best practices of these two server-side runtime technologies.

_- liran- Node speaker
LinkedIn_SM_icon_RN22
Liran Tal
Developer Advocate
Snyk

Liran Tal is a software developer, and a GitHub Star, world-recognized for his activism in open source communities and advancing web and Node.js security. He engages in security research through his work in the OpenJS Foundation and the Node.js ecosystem security working group, and further promotes open source supply chain security as an OWASP project lead. Liran is also a published author of Essential Node.js Security and O'Reilly's Serverless Security. At Snyk, he is leading the developer advocacy team and on a mission to empower developers with better dev-first security.

Cancellation Policy

Sponsor Cancellation:

In case of cancellation of the event, we will offer a full refund to all attendees and sponsors.

Attendee cancellations:

Up to 30 days prior to the event – 100% Refund.
30-14 days prior to the event – 50% Refund.
No refund will be offered later than that.