1.8 KiB
1.8 KiB
Dependency decisions
This record explains dependencies that are not part of the Go standard library.
All versions are exact in go.mod, generated code, or the toolchain image.
| Dependency | Purpose | Decision |
|---|---|---|
| coder/websocket 1.8.15 | Context-aware WebSocket server/client transport | Maintained Go WebSocket implementation with bounded message reads and explicit Ping support; RVBox keeps protobuf validation, session fencing, origin policy, and backpressure in its own code. |
| Buf 1.72.0 | Protobuf formatting, linting, and deterministic generation | Current stable release when the v1 implementation began; installed only in the toolchain image. |
| protoc 35.0 | Protobuf compiler and well-known includes | Pinned archive with a checked SHA-256; included even though normal generation is driven by Buf. |
| protobuf-go 1.36.12 | Go protobuf runtime and generator | Official maintained Go protobuf implementation. |
| protoc-gen-go-grpc 1.6.2 | Go gRPC generator | Official maintained gRPC-Go generator. |
| google/uuid 1.6.0 | Parse canonical UUIDs and verify RFC variant/version bits | Stable maintained package; RVBox owns the monotonic UUIDv7 generator so clock and ordering behavior remain directly testable. |
| go-toml/v2 2.3.1 | Strict configuration decoding | Last maintained release line before TOML 1.1 parsing was enabled; RVBox v1 intentionally accepts TOML 1.0 only. |
| klauspost/compress 1.19.0 | Zstandard command-output compression | Maintained pure-Go codec with decoder memory controls; RVBox additionally limits streamed decoded output before allocation. |
| modernc.org/sqlite 1.57.0 | Durable server/client metadata | Maintained CGO-free SQLite driver with Linux/Windows support and defensive-mode DSN support; its exact generated-code-matched libc version is pinned by go.mod. |