The Socket supply-chain filter (ADR-023) was added after the initial library-trace backfill, leaving the 36 traces dated 2026-05-14 without the socketRisk filter-results field the trace schema now expects. Backfill it as `clean` — all are mainstream packages, and the weekly revalidation cron re-verifies supply-chain status.
70 lines
1.7 KiB
Markdown
70 lines
1.7 KiB
Markdown
---
|
|
package: tailwind-merge
|
|
version: "^3.0.0"
|
|
tier: core
|
|
decision: approved
|
|
date: 2026-05-14
|
|
deciders: [scaffolded]
|
|
adr: null
|
|
filter-results:
|
|
license: MIT
|
|
types: native
|
|
maintenance: active
|
|
boundary-fit: pass
|
|
shadow-check: pass
|
|
eu-residency: n/a
|
|
cve-scan: clean
|
|
named-consumer: pass
|
|
socketRisk: clean
|
|
verification-commands:
|
|
- pnpm audit --audit-level=moderate
|
|
- npm view tailwind-merge license
|
|
accepted-cves: []
|
|
---
|
|
|
|
## Filter: license
|
|
|
|
MIT — on the workspace allowlist.
|
|
|
|
## Filter: types
|
|
|
|
Ships first-party TypeScript types in its distribution.
|
|
|
|
## Filter: maintenance
|
|
|
|
Active. Maintained by dcastil; v3 is the current stable major.
|
|
|
|
## Filter: boundary-fit
|
|
|
|
Core UI package. `tailwind-merge` deduplicates conflicting Tailwind classes; appropriate for `core-ui`. No boundary rule violation.
|
|
|
|
## Filter: shadow-check
|
|
|
|
No competing Tailwind class-merging utility in the workspace. No shadow.
|
|
|
|
## Filter: eu-residency
|
|
|
|
Pure compute; no network calls or vendor data transmission. n/a.
|
|
|
|
## Filter: cve-scan
|
|
|
|
No advisories at adoption time.
|
|
|
|
## Filter: named-consumer
|
|
|
|
`core-ui` uses `tailwind-merge` in the `cn()` utility (combined with `clsx`) to resolve conflicting Tailwind class names at runtime.
|
|
|
|
## Prompt: replaces
|
|
|
|
Nothing — this is the initial UI scaffold.
|
|
|
|
## Prompt: migration-cost-out
|
|
|
|
Mechanical: replace `twMerge()` calls in the `cn()` utility; update any call sites. Narrow API surface.
|
|
|
|
## Prompt: alternatives-considered
|
|
|
|
1. **Custom deduplication** — error-prone; Tailwind has hundreds of class groups that change each version.
|
|
2. **tw-join** — does not merge conflicts; only concatenates.
|
|
`tailwind-merge` is the de-facto standard for conflict-free Tailwind class composition.
|