Skip to content

release: v1.5.3 - fail clearly on Node without require(esm) - #70

Merged
cldmv-bot[bot] merged 10 commits into
masterfrom
next
Oct 4, 2026
Merged

cldmv-bot[bot] merged 10 commits into
masterfrom
next

Conversation

@cldmv-bot

@cldmv-bot cldmv-bot Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

vitest-runner v1.5.3 Changelog

Release Date: October 2026
Release Type: Patch
Branch: release/1.5.3


Overview

This release changes how dist/index.cjs loads the ES module build. The CommonJS entry no longer goes through createRequire, which kept bundlers from seeing the dependency, and it now fails with a clear, actionable error on a Node.js version that cannot require() an ES module. New node:test checks run the built CommonJS entry point on every test and coverage run.

The ES module build, the CLI and the run() API are unchanged, and on Node.js versions with require(esm) (20.19+ and 22.12+), require("@cldmv/vitest-runner") returns the same named exports as before.

It also raises engines.node to >=22.12.0 (#73). The old >=20.19.0 floor was never true: the runtime dependency chalk 6 needs Node.js 22, the current vitest 5 peer needs ^22.12.0, and CI only ever tested 22.12 and later.


💥 Breaking Changes

Node.js 20 is no longer supported (#73, fixes #72)

engines.node moves from >=20.19.0 to >=22.12.0, despite this being a patch release. In practice Node.js 20 already stopped working cleanly in v1.5.2: chalk 6.0.1 declares Node.js 22 or later, so Node.js 20 installs printed an EBADENGINE warning and failed outright under engine-strict, and vitest 5 does not install on Node.js 20 at all. The floor now says what the package actually needs.

🐛 Bug Fixes

The CommonJS entry uses a plain require() (#69)

src/cjs-shim.cjs, which the build copies verbatim to dist/index.cjs, loaded ./index.mjs through createRequire(__filename). A .cjs file already has require, so createRequire added nothing, and it hid the dependency from bundlers such as esbuild and webpack, which detect dependencies from static require("…") calls. The shim now calls require("./index.mjs") directly and exports its result.

require() fails clearly on Node.js without require(esm) (#69)

On a Node.js version without synchronous require(esm) (before 20.19 on the 20.x line, or before 22.12), the shim's require() threw a generic ERR_REQUIRE_ESM that pointed at the package's internals. The shim now checks process.features.require_module first and, when it is missing, throws an error with the same ERR_REQUIRE_ESM code and a message naming the package, the required versions and the running version:

@cldmv/vitest-runner: require() needs Node.js ^20.19.0 or >=22.12.0 (this is v20.18.0). On older Node.js, load the package with import() instead.

Code that catches ERR_REQUIRE_ESM by code keeps working.

🧪 Tests

  • New tests/cjs/entry.test.cjs, run with node --test by a new test:cjs script after a fresh npm run build. It checks that require() of the built package returns the same named exports as import, and that the version check throws the new error when require(esm) is unavailable.
  • npm test, npm run test:coverage and npm run ci:coverage now run test:cjs after Vitest, so CI exercises the published CommonJS entry point.

📄 License

  • The package is relicensed from MIT to Apache-2.0: LICENSE now carries the Apache License 2.0 text and package.json declares "license": "Apache-2.0".

📚 Documentation

  • NEW: docs/changelog/v1/v1.5.3.md: this changelog.
  • NEW: changelog files for every earlier release that shipped without one: v1.0.0, v1.0.1, v1.0.2, v1.0.3, v1.1.0, v1.2.0, v1.3.0, v1.3.1, v1.3.2, v1.3.3 and v1.5.2.
  • README restructured to the CLDMV layout (badges, What's New, Key Features, Installation with Node.js requirements, Quick Start, then the existing CLI, API and coverage reference). The install commands now use the scoped package name @cldmv/vitest-runner, and the Node.js requirement matches engines.node.

🔧 Dependencies

No dependency updates.


Upgrade notes

  • Node.js 22.12 or later is required. On Node.js 20, stay on v1.5.1 (the last release before chalk 6), or upgrade Node.js. Everyone already on Node.js 22.12+ gets a drop-in update from v1.5.2.
  • On a Node.js version without require(esm), require() now fails with a clearer message and the same ERR_REQUIRE_ESM code.
👥 Contributors

coverage

Metric Coverage
Statements 99.4%
Branches 99.6%
Functions 100.0%
Lines 99.3%

Avg: 99.5% · 79b31f7 · Node lts/*

Co-authored-by: Shinrai Shinrai@users.noreply.github.com

Shinrai and others added 3 commits October 3, 2026 10:42
src/cjs-shim.cjs loaded dist/index.mjs via createRequire(__filename),
but a .cjs file already has a plain require() available — createRequire
is unnecessary and breaks static-require detection in bundlers like
esbuild/webpack. Switched to a plain require("./index.mjs").

On Node.js versions without require(esm) (before 20.19 / 22.12), that
plain require() would fail with a bare, confusing ERR_REQUIRE_ESM.
Check process.features.require_module up front and throw a clear
message pointing at import() instead.

tests/cjs: node:test checks run by npm test/coverage after Vitest:
require() returns the same named exports as import, and the version
check fires when require(esm) is off.
@cldmv-bot cldmv-bot Bot added ! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: patch This release contains only backwards-compatible bug fixes type: bug Something is broken or not behaving as expected area: core Touches core library / runtime source code area: tests Touches test files, fixtures, or test infrastructure type: dependencies Relates to dependency updates, version bumps, or package management labels Oct 3, 2026
@cldmv-bot

cldmv-bot Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor Author

🔒 Dependency Review

  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses
  • ✅ 0 denied package(s)
  • ✅ 0 package(s) with OpenSSF Scorecard score < 3

Full job summary

@cldmv-bot

cldmv-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Bundle size increased

File Raw Δ Raw Gzipped Δ Gzipped
bin/vitest-runner.mjs 31.6 kB — 11.0 kB —
dist/index.cjs 1.9 kB +614 B (+44.9%) ⚠️ 1.1 kB +314 B
dist/index.mjs 25.7 kB — 9.1 kB —
Total 59.2 kB +614 B 21.1 kB +314 B

📊 Generated by bundle-size. Brotli sizes also measured but omitted from the table for brevity.

Shinrai and others added 7 commits October 3, 2026 16:55
These releases shipped without a per-version changelog file. Each file
is written from the diff against the previous release, notes that
v1.3.0–v1.3.3 never reached npm (their changes first shipped in
v1.4.2), and records the behaviour changes in minor releases: v1.1.0
stopped --log-file from enabling coverage, and v1.2.0 raised
engines.node to >=20.19.0. The v1.5.2 notes record that its chalk 6
dependency declares Node.js >=22 while engines.node still reads
>=20.19.0.
Adds docs/changelog/v1/v1.5.3.md for the pending release (#69: the
CommonJS entry uses a plain require() and fails clearly on Node.js
without require(esm)) and promotes v1.5.3 to the README What's New
Latest block.

The README follows the CLDMV layout: intro and tagline, badges, What's
New, Key Features, Installation with Node.js requirements, Quick Start,
then the existing CLI, API, coverage and layout reference, followed by
Documentation, Contributing, Links and License. Install commands and
code examples now use the scoped @cldmv/vitest-runner name, the Node.js
requirement matches engines.node instead of claiming Node.js 18, and
the source layout describes dist/index.cjs as the thin shim it is.
Replace the MIT license with the Apache License 2.0 in LICENSE, package.json, the README and the v1.5.3 changelog.
The runtime dependency chalk 6 declares node >=22, the current vitest peer
(5.x) needs ^22.12.0 || ^24 || >=26, and CI tests from 22.12.0, so the
declared >=20.19.0 floor was never true: Node.js 20 installs warned with
EBADENGINE and failed under engine-strict.

Fixes #72
#73 raises engines.node to >=22.12.0 (fixes #72). Record it under
Breaking Changes with the upgrade path (stay on v1.5.1 for Node.js 20),
and update the README Requirements and the What's New Latest block.
@cldmv-bot cldmv-bot Bot added the type: documentation Relates to docs, README updates, guides, or inline code comments label Oct 4, 2026
@cldmv-bot
cldmv-bot Bot merged commit a554cdb into master Oct 4, 2026
45 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: core Touches core library / runtime source code area: tests Touches test files, fixtures, or test infrastructure ! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: patch This release contains only backwards-compatible bug fixes type: bug Something is broken or not behaving as expected type: dependencies Relates to dependency updates, version bumps, or package management type: documentation Relates to docs, README updates, guides, or inline code comments

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Runtime dependency chalk 6 requires Node.js >=22, but engines says >=20.19.0

1 participant