Public source validation / validate (push) Failing after 3m8s
60 lines
2.4 KiB
Markdown
60 lines
2.4 KiB
Markdown
# Dependency policy
|
|
|
|
A production dependency is accepted only when it:
|
|
|
|
- solves a real requirement better than a small maintained implementation;
|
|
- is actively maintained;
|
|
- has a compatible license;
|
|
- has no unresolved unacceptable security issue;
|
|
- supports the selected runtime/browser versions;
|
|
- has clear upgrade and removal paths;
|
|
- does not require excessive privilege or bundle size.
|
|
|
|
## Selection record
|
|
|
|
For material dependencies record:
|
|
- package and version range;
|
|
- purpose;
|
|
- alternatives considered;
|
|
- maintenance/release activity;
|
|
- license;
|
|
- security check;
|
|
- bundle/image/runtime impact;
|
|
- locking strategy.
|
|
|
|
This may be an ADR or a dependency manifest note.
|
|
|
|
## Default choices to validate during M0/M1
|
|
|
|
- React + TypeScript + Vite.
|
|
- GridStack for layout.
|
|
- uPlot for high-volume time series.
|
|
- ECharts for complex visualizations.
|
|
- TanStack Query for server state.
|
|
- Accessible UI primitives/component library.
|
|
- Go HTTP/router, OIDC/JWT and PostgreSQL libraries selected from maintained options.
|
|
- PostgreSQL migration tool with explicit CLI and rollback strategy.
|
|
- Playwright and automated accessibility tooling.
|
|
- Testcontainers for integration tests.
|
|
|
|
These are defaults, not permission to install blindly. Verify current supported versions and compatibility.
|
|
|
|
## Rules
|
|
|
|
- Commit lockfiles.
|
|
- Prefer exact image tags/digests in production records.
|
|
- Avoid duplicate libraries for the same concern.
|
|
- Do not use abandonware because an example already uses it.
|
|
- Do not add Redis, Kafka, Elasticsearch or a second metrics database without measured need and ADR.
|
|
- Remove unused dependencies immediately.
|
|
- Run dependency/license/vulnerability checks at milestones and release.
|
|
|
|
|
|
## M4-06 WebSocket selection
|
|
|
|
- Package/version: github.com/coder/websocket v1.8.15, pinned in go.mod and go.sum.
|
|
- Purpose: RFC6455 server upgrade, context-aware reads/writes, ping/pong and bounded frame reads for the authenticated live endpoint.
|
|
- Alternatives considered: hand-rolled RFC6455 handling was rejected because it increases protocol and security risk; gorilla/websocket was not needed for this narrow API; golang.org/x/net/websocket is deprecated.
|
|
- Maintenance/security: current upstream release was resolved locally on 2026-08-01; the module has zero transitive dependencies and the source license is permissive MIT.
|
|
- Runtime impact: server-only dependency, no browser bundle or privilege change; SetReadLimit and write deadlines enforce the endpoint budget.
|