← Corpus / augment-it / reminder

Libraries We Do Not Use — Ever

A hard denylist of packages this codebase has removed on purpose. Do not import them, do not assume they are installed, do not re-add them.

Path
reminders/Libraries-we-Do-Not-Use-Ever.md
Authors
Michael Staton
Augmented with
Claude Code on Claude Opus 4.8
Tags
Reminder · Dependencies · Augment-It

Libraries We Do Not Use — Ever

Why Care?

Packages on this list were removed deliberately — they caused real errors and were replaced with hand-rolled code or a platform built-in. Re-importing one, or assuming it’s installed, silently reintroduces the exact problem it was removed to fix. On 2026-08-02 a one-property backend change was blocked for three rounds because a helper script still had a stale require('ws') in it — the library had already been ripped out, so the script crashed with Cannot find module 'ws' the moment it ran.

The rules

  1. Never assume a library is installed. Check package.json (and that it actually resolves) before importing anything.
  2. Never install a library to make a script work. If a dependency is missing, that is usually a signal it was removed on purpose — ask, or hand-roll it. See [[feedback_minimal_dependencies_hand_roll]].
  3. Prefer platform built-ins. Node ≥ 22 has a global WebSocket and global fetch — use those, not packages.

The denylist

PackageWhy it’s bannedUse instead
wsRemoved for causing errors. Any script still importing it is stale and will crash with Cannot find module 'ws'.Node’s built-in global WebSocket (Node ≥ 18/22), or hand-rolled WebSocket handling.

Known offenders to fix when next touched

  • scripts/prove-didi-auth.mjs — still does require('ws') at the top. It needs rewriting onto the native global WebSocket (which does not take a ws-style headers option, so the didi_session cookie has to be carried a different way) before it can run again.

See also

  • [[feedback_minimal_dependencies_hand_roll]] — the standing rule this reminder makes concrete.