docs: introduce library evaluation policy (ADR-022 + PRD)

- ADR-022 codifies the tiered library-evaluation policy: 8 hard
  auto-reject filters (license, types, maintenance, boundary-fit,
  shadow-check, EU residency, CVE scan, named consumer), 3
  discussion prompts, per-decision trace artifact at
  docs/library-decisions/, and a 4-layer enforcement stack
  (Claude PreToolUse/PostToolUse hook -> evaluate-library skill ->
  pre-commit hook -> sandcastle reviewer prompt). Mirrors the
  conformance-system latency pattern from ADR-012.
- PRD at docs/work/prds/2026-05-14-library-evaluation-policy.prd.md
  seeds the implementation epic; status: approved, ready for
  \`pnpm work decompose\`.
- Glossary gains "Library trace" + "Pre-shipped trace" entries
  referenced by both artifacts.

Catalyst: the 2026-05-14 grill session nearly adopted
trpc-to-openapi + zod-to-json-schema before someone asked who the
HTTP consumer was. Honest answer: none -- all callers are TS via
createCaller. This policy makes that question structurally
unavoidable for any future feature- or core-tier dep.
This commit is contained in:
2026-05-14 06:41:28 +02:00
parent 52af9f1fdd
commit 7f1a8d0212
4 changed files with 612 additions and 1 deletions

View File

@@ -1,5 +1,5 @@
{
"updated_at": "2026-05-13T18:41:19.463Z",
"updated_at": "2026-05-14T04:41:30.276Z",
"epics": {
"2026-05-13-binder-wrap-helper": {
"status": "done",