EXPECTED RED until the Issue #511 ESM sweep agent merges createRequire
fixes for src/server.ts and src/cli.ts. The current
server.bundle.mjs and cli.bundle.mjs ship with esbuild's throwing
'Dynamic require of ...' shim embedded — exactly the state that
broke users in #511.
This test is the *forcing function* that turns G3 from advisory into
load-bearing. Skipping it would let the sweep land without proof the
guardrail wired through to real bundles. Once the sweep merges and the
next bundle.yml run rebuilds, this test flips green and the invariant
is permanently locked in for every PR.
Adds 'assert-bundle' npm script targeting all five produced bundles,
and chains it from 'build' so every build that finishes successfully
has guaranteed-clean ESM output. Pretest, prepublishOnly, and CI Build
steps all inherit the assertion.
Test pins both the script presence and the chain wiring so a future
config refactor can't silently drop the guardrail.
Pin the negative-path behavior. A bundle that uses
createRequire(import.meta.url) at module top has no shim and no bare
require('node:...') strings — the script must accept it.
G3 guardrail (Issue #511 class). Adds scripts/assert-bundle.mjs which
scans bundle files for the esbuild throwing-require shim and exits 1
if any forbidden pattern is matched.
Tracer-bullet RED→GREEN: fixture bundle containing the shim string is
correctly rejected.