← Corpus / augment-it / reminder
Libraries We Do Not Use — Ever
A hard denylist of packages this codebase has removed on purpose. Do not import them, do not assume they are installed, do not re-add them.
- Path
- reminders/Libraries-we-Do-Not-Use-Ever.md
- Authors
- Michael Staton
- Augmented with
- Claude Code on Claude Opus 4.8
- Tags
- Reminder · Dependencies · Augment-It
Libraries We Do Not Use — Ever
Why Care?
Packages on this list were removed deliberately — they caused real
errors and were replaced with hand-rolled code or a platform built-in.
Re-importing one, or assuming it’s installed, silently reintroduces the
exact problem it was removed to fix. On 2026-08-02 a one-property backend
change was blocked for three rounds because a helper script still had a
stale require('ws') in it — the library had already been ripped out, so
the script crashed with Cannot find module 'ws' the moment it ran.
The rules
- Never assume a library is installed. Check
package.json(and that it actually resolves) before importing anything. - Never install a library to make a script work. If a dependency is missing, that is usually a signal it was removed on purpose — ask, or hand-roll it. See [[feedback_minimal_dependencies_hand_roll]].
- Prefer platform built-ins. Node ≥ 22 has a global
WebSocketand globalfetch— use those, not packages.
The denylist
| Package | Why it’s banned | Use instead |
|---|---|---|
ws | Removed for causing errors. Any script still importing it is stale and will crash with Cannot find module 'ws'. | Node’s built-in global WebSocket (Node ≥ 18/22), or hand-rolled WebSocket handling. |
Known offenders to fix when next touched
scripts/prove-didi-auth.mjs— still doesrequire('ws')at the top. It needs rewriting onto the native globalWebSocket(which does not take aws-styleheadersoption, so thedidi_sessioncookie has to be carried a different way) before it can run again.
See also
- [[feedback_minimal_dependencies_hand_roll]] — the standing rule this reminder makes concrete.