Skip to content

Remove unused Zustand runtime dependency #166

Description

@atomantic

Problem

The client ships a direct Zustand dependency despite having no Zustand store, hook, import, dynamic import, or type use.

Evidence

client/package.json:22 declares zustand as ^5.0.12; the exact lockfile resolves zustand@5.0.14. A repository-wide source, test, script, and configuration search found zero references outside that manifest declaration (zero imported symbols and zero call sites across zero files). npm ls --package-lock-only --all zustand shows it is present only as the direct client dependency, not through a kept package. The application already uses component-local React state and does not expose a Zustand integration point.

Impact

Removing the unused runtime package eliminates an install and client-bundle dependency with no product behavior change.

Implementation plan

Remove zustand from client/dependencies, regenerate the root lockfile with npm install --package-lock-only --ignore-scripts, and rebuild the Vite client to confirm the generated bundle has no dependency on it. No owned state-management replacement is required.

Acceptance criteria

zustand is absent from the client manifest and root lockfile; no source imports it; the production client build and test suite pass without adding a replacement state library.

Verification

Run npm install --package-lock-only --ignore-scripts, npm ls zustand, npm run build -w client, and the applicable client tests.

Dependencies and related work

Independent of #120 and #149#155. This is not the socket.io-client advisory root cause: socket.io-client remains transitively required by portos-ai-toolkit, so it is intentionally excluded from this claim.

Scope

Replacement complexity: Trivial. Likely files: client/package.json, package-lock.json. Non-goals: redesigning application state, adding a state library, or updating the toolkit's dependencies.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    depsDependency audit findingplanClaimable backlog itemseverity:mediumMedium severity

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions