Generator-emitted scaffold (pnpm turbo gen core-package realtime) plus the story-00-precedent coverage repairs (coverage provider devDep, symbols.ts exclude + tested allowlist mirror) and three minimal tests covering generator-emitted realtime code the template suite misses. Squash of 31d85e0 + review-fix cf11b38. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
1.9 KiB
package, version, tier, decision, date, deciders, adr, filter-results, verification-commands, accepted-cves
| package | version | tier | decision | date | deciders | adr | filter-results | verification-commands | accepted-cves | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| socket.io | ^4.7.0 | core | approved | 2026-05-14 |
|
adr-016 |
|
|
Filter: license
MIT — on the workspace allowlist.
Filter: types
Ships first-party TypeScript types in its distribution.
Filter: maintenance
Active. Maintained by the Socket.IO team; frequent releases and active issue tracker.
Filter: maintenance
Active. Regular releases; widely deployed in production.
Filter: boundary-fit
ADR-016 §R2 explicitly designates core-realtime as the sole allowed home for socket.io. Boundary rule no-direct-socket-io enforces this in ESLint.
Filter: shadow-check
No competing realtime transport in the workspace. No shadow.
Filter: eu-residency
Self-hosted server; the library itself does not transmit data to any vendor endpoint.
Filter: cve-scan
No advisories at adoption time.
Filter: named-consumer
core-realtime wraps socket.io to provide the IRealtimeServer abstraction (ADR-016).
Prompt: replaces
Nothing — this is the initial realtime scaffolding. No prior transport to retire.
Prompt: migration-cost-out
Hard: channel descriptors, handler signatures, and server-side broadcast API are all shaped around socket.io semantics. Replacing requires re-implementing the abstraction layer.
Prompt: alternatives-considered
- ws — lower-level, no rooms or namespaces; would require significant protocol work.
- Ably / Pusher — vendor-hosted; eu-residency risk and ongoing cost. Socket.IO is the established standard for this use-case and is fully self-hostable.