Files
agentic-dev/packages/core-realtime/docs/library-decisions/2026-05-14-socket.io.md
Danijel Martinek e50306cbf6 feat(core-realtime): scaffold realtime optional core
Generator-emitted scaffold (pnpm turbo gen core-package realtime) plus
the story-00-precedent coverage repairs (coverage provider devDep,
symbols.ts exclude + tested allowlist mirror) and three minimal tests
covering generator-emitted realtime code the template suite misses.
Squash of 31d85e0 + review-fix cf11b38.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 20:35:09 +02:00

1.9 KiB

package, version, tier, decision, date, deciders, adr, filter-results, verification-commands, accepted-cves
package version tier decision date deciders adr filter-results verification-commands accepted-cves
socket.io ^4.7.0 core approved 2026-05-14
scaffolded
adr-016
license types maintenance boundary-fit shadow-check eu-residency cve-scan named-consumer
MIT native active pass pass self-hostable clean pass
pnpm audit --audit-level=moderate
npm view socket.io license

Filter: license

MIT — on the workspace allowlist.

Filter: types

Ships first-party TypeScript types in its distribution.

Filter: maintenance

Active. Maintained by the Socket.IO team; frequent releases and active issue tracker.

Filter: maintenance

Active. Regular releases; widely deployed in production.

Filter: boundary-fit

ADR-016 §R2 explicitly designates core-realtime as the sole allowed home for socket.io. Boundary rule no-direct-socket-io enforces this in ESLint.

Filter: shadow-check

No competing realtime transport in the workspace. No shadow.

Filter: eu-residency

Self-hosted server; the library itself does not transmit data to any vendor endpoint.

Filter: cve-scan

No advisories at adoption time.

Filter: named-consumer

core-realtime wraps socket.io to provide the IRealtimeServer abstraction (ADR-016).

Prompt: replaces

Nothing — this is the initial realtime scaffolding. No prior transport to retire.

Prompt: migration-cost-out

Hard: channel descriptors, handler signatures, and server-side broadcast API are all shaped around socket.io semantics. Replacing requires re-implementing the abstraction layer.

Prompt: alternatives-considered

  1. ws — lower-level, no rooms or namespaces; would require significant protocol work.
  2. Ably / Pusher — vendor-hosted; eu-residency risk and ongoing cost. Socket.IO is the established standard for this use-case and is fully self-hostable.