Skip to content

fix: parse .cjs / .cts / .js within "type": "commonjs" as CommonJS#8455

Merged
graphite-app[bot] merged 1 commit intomainfrom
02-25-fix_parse_.cjs___.cts___.js_within_type_commonjs_as_commonjs
Feb 25, 2026
Merged

fix: parse .cjs / .cts / .js within "type": "commonjs" as CommonJS#8455
graphite-app[bot] merged 1 commit intomainfrom
02-25-fix_parse_.cjs___.cts___.js_within_type_commonjs_as_commonjs

Conversation

@sapphi-red
Copy link
Member

@sapphi-red sapphi-red commented Feb 25, 2026

.cjs / .cts / .js with the closest package.json with "type": "commonjs" will now be parsed as CJS, which will allow non-strict syntaxes.

Part of #7009.

Copy link
Member Author


How to use the Graphite Merge Queue

Add the label graphite: merge-when-ready to this PR to add it to the merge queue.

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has enabled the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

This stack of pull requests is managed by Graphite. Learn more about stacking.

@netlify
Copy link

netlify bot commented Feb 25, 2026

Deploy Preview for rolldown-rs canceled.

Name Link
🔨 Latest commit 8b05737
🔍 Latest deploy log https://app.netlify.com/projects/rolldown-rs/deploys/699e9e8fd1081d0009e926d2

@sapphi-red sapphi-red force-pushed the 02-25-fix_parse_.cjs___.cts___.js_within_type_commonjs_as_commonjs branch from ec1fc01 to a077b55 Compare February 25, 2026 04:12
@sapphi-red sapphi-red marked this pull request as ready for review February 25, 2026 04:32
Copilot AI review requested due to automatic review settings February 25, 2026 04:32
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adjusts Rolldown’s JS/TS parsing mode so that modules identified as CommonJS (by extension or closest package.json "type": "commonjs") are parsed as CommonJS/script (sloppy-capable) instead of ESM/strict, addressing cases like assigning to arguments (Issue #7009).

Changes:

  • Switch parse_to_ecma_ast to choose oxc::SourceType based on ResolvedId.module_def_format (CJS vs ESM).
  • Update/extend integration fixtures and snapshots to reflect .cjs now being treated as CommonJS (e.g., replacing import with require in .cjs fixtures) and add a new cjs_arguments regression fixture.
  • Add documentation describing the strict-mode parsing limitation and workarounds.

Reviewed changes

Copilot reviewed 11 out of 13 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
docs/in-depth/bundling-cjs.md Documents strict-mode parsing behavior for certain .js cases and a workaround.
crates/rolldown/src/utils/parse_to_ecma_ast.rs Selects oxc SourceType based on ModuleDefFormat to parse CJS as CJS.
crates/rolldown/tests/rolldown/topics/deconflict/cjs_arguments/* Adds a regression fixture covering sloppy-only syntax in CJS (arguments = 1).
crates/rolldown/tests/rolldown/topics/keep_names/issue_7507/src/* Updates the fixture to avoid ESM import in .cjs now that it’s parsed as CJS.
crates/rolldown/tests/rolldown/issues/4289/* Adjusts .cjs fixture + config for node platform; updates expected artifacts.
crates/rolldown/tests/snapshots/integration_rolldown__filename_with_hash.snap Updates hashed-filename expectations due to output changes/new fixture.

@sapphi-red sapphi-red marked this pull request as draft February 25, 2026 04:40
@github-actions
Copy link
Contributor

github-actions bot commented Feb 25, 2026

Benchmarks Rust

  • target: main(87382b7)
  • pr: 02-25-fix_parse_.cjs___.cts___.js_within_type_commonjs_as_commonjs(839a14d)
group                                                        pr                                     target
-----                                                        --                                     ------
bundle/bundle@multi-duplicated-top-level-symbol              1.00     64.9±2.13ms        ? ?/sec    1.00     64.9±2.08ms        ? ?/sec
bundle/bundle@multi-duplicated-top-level-symbol-sourcemap    1.07     73.3±4.64ms        ? ?/sec    1.00     68.4±1.55ms        ? ?/sec
bundle/bundle@rome_ts                                        1.01     96.3±3.13ms        ? ?/sec    1.00     95.7±3.06ms        ? ?/sec
bundle/bundle@rome_ts-sourcemap                              1.02    106.8±3.31ms        ? ?/sec    1.00    104.9±1.62ms        ? ?/sec
bundle/bundle@threejs                                        1.02     34.2±2.23ms        ? ?/sec    1.00     33.7±0.65ms        ? ?/sec
bundle/bundle@threejs-sourcemap                              1.00     38.0±0.89ms        ? ?/sec    1.02     38.6±1.95ms        ? ?/sec
bundle/bundle@threejs10x                                     1.03    360.9±9.56ms        ? ?/sec    1.00    349.2±4.83ms        ? ?/sec
bundle/bundle@threejs10x-sourcemap                           1.00    402.2±5.29ms        ? ?/sec    1.00    401.6±7.70ms        ? ?/sec
scan/scan@rome_ts                                            1.01     74.3±1.42ms        ? ?/sec    1.00     73.6±1.47ms        ? ?/sec
scan/scan@threejs                                            1.00     26.4±1.63ms        ? ?/sec    1.00     26.3±0.45ms        ? ?/sec
scan/scan@threejs10x                                         1.00    265.9±4.28ms        ? ?/sec    1.00    265.7±3.68ms        ? ?/sec

@sapphi-red sapphi-red force-pushed the 02-25-fix_parse_.cjs___.cts___.js_within_type_commonjs_as_commonjs branch from a077b55 to 839a14d Compare February 25, 2026 05:01
@socket-security
Copy link

socket-security bot commented Feb 25, 2026

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm markdown-it is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: pnpm-lock.yamlnpm/markdown-it@14.1.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/markdown-it@14.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@sapphi-red sapphi-red marked this pull request as ready for review February 25, 2026 05:04
Copilot AI review requested due to automatic review settings February 25, 2026 05:04
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 19 out of 21 changed files in this pull request and generated 2 comments.

Copy link
Member Author

sapphi-red commented Feb 25, 2026

Merge activity

  • Feb 25, 5:22 AM UTC: The merge label 'graphite: merge-when-ready' was detected. This PR will be added to the Graphite merge queue once it meets the requirements.
  • Feb 25, 7:02 AM UTC: sapphi-red added this pull request to the Graphite merge queue.
  • Feb 25, 7:12 AM UTC: Merged by the Graphite merge queue.

@sapphi-red sapphi-red force-pushed the 02-25-fix_parse_.cjs___.cts___.js_within_type_commonjs_as_commonjs branch from 839a14d to d509445 Compare February 25, 2026 06:50
…monJS (#8455)

`.cjs` / `.cts` / `.js` with the closest `package.json` with `"type": "commonjs"` will now be parsed as CJS, which will allow non-strict syntaxes.

Part of #7009.
@graphite-app graphite-app bot force-pushed the 02-25-fix_parse_.cjs___.cts___.js_within_type_commonjs_as_commonjs branch from d509445 to 8b05737 Compare February 25, 2026 07:02
@graphite-app graphite-app bot merged commit 8b05737 into main Feb 25, 2026
34 checks passed
@graphite-app graphite-app bot deleted the 02-25-fix_parse_.cjs___.cts___.js_within_type_commonjs_as_commonjs branch February 25, 2026 07:12
graphite-app bot pushed a commit that referenced this pull request Feb 26, 2026
This PR partially reverts #8455. `.js` with the closest `package.json` with `"type": "commonjs"` will now be parsed as ESM for now as that caused tests in Vite repo to fail. For example:
```
[PARSE_ERROR] Error: Cannot use import statement outside a module
   ╭─[ node_modules/.pnpm/@babel+runtime@7.28.6/node_modules/@babel/runtime/helpers/esm/slicedToArray.js:1:1 ]
   │
 1 │ import arrayWithHoles from "./arrayWithHoles.js";
   │ ───┬──
   │    ╰────
───╯
```
shulaoda pushed a commit that referenced this pull request Feb 26, 2026
This PR partially reverts #8455. `.js` with the closest `package.json`
with `"type": "commonjs"` will now be parsed as ESM for now as that
caused tests in Vite repo to fail. For example:
```
[PARSE_ERROR] Error: Cannot use import statement outside a module
   ╭─[ node_modules/.pnpm/@babel+runtime@7.28.6/node_modules/@babel/runtime/helpers/esm/slicedToArray.js:1:1 ]
   │
 1 │ import arrayWithHoles from "./arrayWithHoles.js";
   │ ───┬──  
   │    ╰──── 
───╯
```
This was referenced Feb 26, 2026
shulaoda added a commit that referenced this pull request Feb 26, 2026
## [1.0.0-rc.6] - 2026-02-26

### 💥 BREAKING CHANGES

- css: remove `css_entry_filenames` , `css_chunk_filenames` and related code (#8402) by @hyf0
- css: drop builtin CSS bundling to explore alternative solutions (#8399) by @hyf0

### 🚀 Features

- rust/data-url: use hash as id for data url modules to prevent long string overhead (#8420) by @hyf0
- validate bundle stays within output dir (#8441) by @sapphi-red
- rust: support `PluginOrder::PinPost` (#8417) by @hyf0
- support `ModuleType:Copy` (#8407) by @hyf0
- expose `ESTree` types from `rolldown/utils` (#8400) by @sapphi-red

### 🐛 Bug Fixes

- incorrect sourcemap when postBanner/postFooter is used with shebang (#8459) by @Copilot
- resolver: disable node_path option to align ESM resolver behavior (#8472) by @sapphi-red
- parse `.js` within `"type": "commonjs"` as ESM for now (#8470) by @sapphi-red
- case-insensitive filename conflict detection for chunk deduplication (#8458) by @Copilot
- prevent inlining CJS exports that are mutated by importers (#8456) by @IWANABETHATGUY
- parse `.cjs` / `.cts` / `.js` within `"type": "commonjs"` as CommonJS (#8455) by @sapphi-red
- plugin/copy-module: correct hooks' priority (#8423) by @hyf0
- plugin/chunk-import-map: ensure `render_chunk_meta` run after users plugin (#8422) by @hyf0
- rust: correct hooks order of `DataUriPlugin` (#8418) by @hyf0
- `jsx.preserve` should also considering tsconfig json preserve (#8324) by @IWANABETHATGUY
- `deferred_scan_data.rs "Should have resolved id: NotFound"` error (#8379) by @sapphi-red
- cli: require value for `--dir`/`-d` and `--file`/`-o` (#8378) by @Copilot
- dev: avoid mutex deadlock caused by inconsistent lock order (#8370) by @sapphi-red

### 🚜 Refactor

- watch: rename TaskStart/TaskEnd to BundleStart/BundleEnd (#8463) by @hyf0
- rust: rename `rolldown_plugin_data_uri` to `rolldown_plugin_data_url` (#8421) by @hyf0
- bindingify-build-hook: extract helper for PluginContextImpl (#8438) by @ShroXd
- give source loading a proper name (#8436) by @IWANABETHATGUY
- ban holding DashMap refs across awaits (#8362) by @sapphi-red

### 📚 Documentation

- add glob pattern usage example to input option (#8469) by @IWANABETHATGUY
- remove `https://rolldown.rs` from links in reference docs (#8454) by @sapphi-red
- mention execution order issue in `output.codeSplitting` docs (#8452) by @sapphi-red
- clarify `output.comments` behavior a bit (#8451) by @sapphi-red
- replace npmjs package links with npmx.dev (#8439) by @Boshen
- reference: add `Exported from` for values / types exported from subpath exports (#8394) by @sapphi-red
- add JSDocs for APIs exposed from subpath exports (#8393) by @sapphi-red
- reference: generate reference pages for APIs exposed from subpath exports (#8392) by @sapphi-red
- avoid pipe character in codeSplitting example to fix broken rendering (#8391) by @IWANABETHATGUY

### ⚡ Performance

- avoid redundant PathBuf allocations in resolve paths (#8435) by @Brooooooklyn
- bump to `sugar_path@2` (#8432) by @hyf0
- use flag-based convergence detection in include_statements (#8412) by @Brooooooklyn

### 🧪 Testing

- execute `_test.mjs` even if `executeOutput` is false (#8398) by @sapphi-red
- add retry to tree-shake/module-side-effects-proxy4 as it is flaky (#8397) by @sapphi-red
- avoid `expect.assertions()` as it is not concurrent test friendly (#8383) by @sapphi-red
- disable `mockReset` option (#8382) by @sapphi-red
- fix flaky failure caused by concurrent resolveId calls (#8381) by @sapphi-red

### ⚙️ Miscellaneous Tasks

- deps: update dependency rollup to v4.59.0 [security] (#8471) by @renovate[bot]
- ai/design: add design doc about watch mode (#8453) by @hyf0
- deps: update oxc resolver to v11.19.0 (#8461) by @renovate[bot]
- ai: introduce progressive spec-driven development pattern (#8446) by @hyf0
- deprecate output.legalComments (#8450) by @sapphi-red
- deps: update dependency oxlint-tsgolint to v0.15.0 (#8448) by @renovate[bot]
- ai: make CLAUDE.md a symlink of AGENTS.md (#8445) by @hyf0
- deps: update rollup submodule for tests to v4.59.0 (#8433) by @sapphi-red
- deps: update test262 submodule for tests (#8434) by @sapphi-red
- deps: update oxc to v0.115.0 (#8430) by @renovate[bot]
- deps: update oxc apps (#8429) by @renovate[bot]
- deps: update npm packages (#8426) by @renovate[bot]
- deps: update rust crate owo-colors to v4.3.0 (#8428) by @renovate[bot]
- deps: update github-actions (#8424) by @renovate[bot]
- deps: update rust crates (#8425) by @renovate[bot]
- deps: update oxc resolver to v11.18.0 (#8406) by @renovate[bot]
- deps: update dependency oxlint-tsgolint to v0.14.2 (#8405) by @renovate[bot]
- ban `expect.assertions` in all fixture tests (#8395) by @sapphi-red
- deps: update oxc apps (#8389) by @renovate[bot]
- ban `expect.assertions` in fixture tests (#8387) by @sapphi-red
- enable lint for `_config.ts` files (#8386) by @sapphi-red
- deps: update dependency oxlint-tsgolint to v0.14.1 (#8385) by @renovate[bot]

Co-authored-by: shulaoda <165626830+shulaoda@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants