mirror of
https://github.com/lancedikson/bowser
synced 2026-09-22 12:05:23 +00:00
Follow-up to the ES5 syntax fix, closing the gaps that investigation left. An ES5-only runtime sandbox. The acorn check catches syntax, but syntax is only half the contract: preset-env lowers syntax and never polyfills library calls, so one `Array.prototype.includes` in the parser source compiles cleanly, passes every test on modern Node, and throws on the browsers es5.js exists for. The new test runs both legacy bundles in a vm context with the post-ES5.1 globals, statics and prototype methods deleted, and asserts bundled.js additionally installs the polyfills its README entry promises. Includes a test that the sandbox really strips, so it cannot quietly pass against a modern global. A consumer type-check across every module resolution mode, run in CI against the packed tarball. attw already checks that types *resolve* per condition; it compiles nothing, so it cannot catch a declaration that resolves correctly and then misdescribes the runtime. Negative cases are asserted too — the maps must stay non-importable as named exports, which is the line index.d.mts draws deliberately and only a failing compile can hold. Also documents two findings that were investigated and deliberately left alone: the bundled.js size increase is the core-js 2 -> 3 upgrade rather than waste, and `useBuiltIns: 'usage'` would shrink it by breaking the documented "all needed polyfills" contract; and the src/*.js ESM-in-CJS wart (publint warnings, Yarn PnP, Node < 20.19) is longstanding and identical on 2.14.1, with the nested-package.json fix blocked on @babel/register. Verified by breaking each guard in turn: an ES6 API call injected into es5.js fails the sandbox test, and an index.d.mts with its `parse` export removed fails all three ESM resolution modes while the CJS modes correctly still pass.