Follow-up to the ES5 syntax fix, closing the gaps that investigation left.
An ES5-only runtime sandbox. The acorn check catches syntax, but syntax is
only half the contract: preset-env lowers syntax and never polyfills library
calls, so one `Array.prototype.includes` in the parser source compiles
cleanly, passes every test on modern Node, and throws on the browsers es5.js
exists for. The new test runs both legacy bundles in a vm context with the
post-ES5.1 globals, statics and prototype methods deleted, and asserts
bundled.js additionally installs the polyfills its README entry promises.
Includes a test that the sandbox really strips, so it cannot quietly pass
against a modern global.
A consumer type-check across every module resolution mode, run in CI against
the packed tarball. attw already checks that types *resolve* per condition;
it compiles nothing, so it cannot catch a declaration that resolves correctly
and then misdescribes the runtime. Negative cases are asserted too — the maps
must stay non-importable as named exports, which is the line index.d.mts
draws deliberately and only a failing compile can hold.
Also documents two findings that were investigated and deliberately left
alone: the bundled.js size increase is the core-js 2 -> 3 upgrade rather than
waste, and `useBuiltIns: 'usage'` would shrink it by breaking the documented
"all needed polyfills" contract; and the src/*.js ESM-in-CJS wart (publint
warnings, Yarn PnP, Node < 20.19) is longstanding and identical on 2.14.1,
with the nested-package.json fix blocked on @babel/register.
Verified by breaking each guard in turn: an ES6 API call injected into es5.js
fails the sandbox test, and an index.d.mts with its `parse` export removed
fails all three ESM resolution modes while the CJS modes correctly still pass.
Two follow-ups to the dual packaging change (#628), found while running a
consumer-facing regression sweep against published 2.14.1.
An exports map is a closed list. Before #628 bowser had no exports map, so
every published file was reachable by subpath; afterwards LICENSE, README.md
and index.d.ts resolved to ERR_PACKAGE_PATH_NOT_EXPORTED. Nothing in the
documented API regressed, but `/// <reference types="bowser/index.d.ts" />`
and tooling that resolves the license by specifier both did. Add the four
non-code files to the map so the published surface matches 2.14.1 exactly,
and assert it in the package smoke test (25 -> 29 checks).
The acceptance suite asserted src/bowser.js and es5.js against the UA corpus
but not bundled.js or bowser.mjs. bowser.mjs is what the `import` condition
resolves to, so it is the file every modern ESM and bundler consumer runs,
and a build regression confined to it would have kept CI green. Assert all
four artifacts against the spec instead.
Verified by injecting a Chrome-parsing regression into bowser.mjs and into
bundled.js separately (each turns the suite red, labelled by artifact), and
by running the new smoke assertions against a pre-fix tarball (exit 1) and
this one (exit 0) on Node 12.16, 14, 18, 20 and 22.