> And it doesn't address the semver malware injection bug demonstrated by colors author
[Not a fan of Bun] In Bun, you can pin versions with package.json just like in node.js
What would address the malware injection when someone chooses to auto-update packages as part of a build?