--- package: socket.io version: "^4.7.0" tier: core decision: approved date: 2026-05-14 deciders: [scaffolded] adr: adr-016 filter-results: license: MIT types: native maintenance: active boundary-fit: pass shadow-check: pass eu-residency: self-hostable cve-scan: clean named-consumer: pass verification-commands: - pnpm audit --audit-level=moderate - npm view socket.io license accepted-cves: [] --- ## Filter: license MIT — on the workspace allowlist. ## Filter: types Ships first-party TypeScript types in its distribution. ## Filter: maintenance Active. Maintained by the Socket.IO team; frequent releases and active issue tracker. ## Filter: maintenance Active. Regular releases; widely deployed in production. ## Filter: boundary-fit ADR-016 §R2 explicitly designates `core-realtime` as the sole allowed home for `socket.io`. Boundary rule `no-direct-socket-io` enforces this in ESLint. ## Filter: shadow-check No competing realtime transport in the workspace. No shadow. ## Filter: eu-residency Self-hosted server; the library itself does not transmit data to any vendor endpoint. ## Filter: cve-scan No advisories at adoption time. ## Filter: named-consumer `core-realtime` wraps socket.io to provide the `IRealtimeServer` abstraction (ADR-016). ## Prompt: replaces Nothing — this is the initial realtime scaffolding. No prior transport to retire. ## Prompt: migration-cost-out Hard: channel descriptors, handler signatures, and server-side broadcast API are all shaped around socket.io semantics. Replacing requires re-implementing the abstraction layer. ## Prompt: alternatives-considered 1. **ws** — lower-level, no rooms or namespaces; would require significant protocol work. 2. **Ably / Pusher** — vendor-hosted; eu-residency risk and ongoing cost. Socket.IO is the established standard for this use-case and is fully self-hostable.