web/yarn.lock replaces web/package-lock.json. yarn import converted
it, so it locks the same package versions with the same integrity
hashes. The web-builder stage pins yarn 1.22.22, the version
script/bootstrap pins, by its sha512 through corepack, and installs
with yarn install --frozen-lockfile. web/build.sh runs the esbuild
that yarn installed rather than npx or an esbuild found on the PATH.
Model: opus-5-5
## Problem
The SPA fails to load with:
```
Uncaught Error: Dynamic require of "preact" is not supported
```
The esbuild config in `web/build.sh` had `--external:preact`, which tells the bundler to leave preact as a `require()` call instead of including it in the bundle. Since the browser has no `require()` function and there is no CDN/import-map loading preact externally, the app crashes immediately.
## Fix
- Remove `--external:preact` from `build.sh` so preact is bundled into `app.js`
- Add `--format=esm` to output proper ESM instead of IIFE with CJS require shims
- Update `index.html` to use `<script type="module">` for ESM compatibility
- Remove the dead fallback build command (was never reached since the first command succeeded)
- Rebuild `dist/app.js` with preact properly inlined (21.1KB minified)
closes#48
Reviewed-on: sneak/chat#49
Co-authored-by: clawbot <clawbot@noreply.example.org>
Co-committed-by: clawbot <clawbot@noreply.example.org>