mrkeyoor.com_
Tue 29 Sept 19:34 UTC
Dev Toolsevaluationupdated 25 Aug 2026

cordis review

Cordis is a TypeScript plugin framework for services that appear, disappear, reload, and depend on one another while a process is running. Its main README is English, and the linked documentation defaults to Chinese but includes a full English section covering contexts, services, events, fibers, and plugin development.

+86stars / 7d
Verdict

Our Cordis checkout installed 432 packages with 0 known vulnerabilities, but both build and test stopped within 10 seconds because the npm-created workspace state did not satisfy Yarn 4.14.1. The framework is interesting for agent hosts and other long-lived systems that need dependency-aware plugins and reversible side effects. Do not base a conservative production architecture on it until the API stabilizes and your team has proved install, reload, failure, and teardown behavior with one package-manager path.

We ran it

Lab card: what happened when we ran cordisScreenshot of cordis (deepseek-harness.github.io/deepseek-harness/reference/cordis-primer)
Install✓ · 120s432 packages · 145 MB
Build✗ · 9s
Tests✗ · 10sran, no count parsed
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo111 files~8,440 lines of source · 0.3 MB · 1 CI workflows

Answers from our run

Does cordis build from source?

Dependencies installed in 120 seconds (432 packages), and the build failed. We cloned commit 8cc9e33 into a clean Debian container with 3 CPUs and no project-specific setup.

Do cordis's tests pass?

The test command failed in our container, and its output did not report a pass or fail count.

Does cordis have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use cordis?

Application teams wanting a stable public API: the README says Cordis is under active development and may change without notice.

What are the alternatives to cordis?

Koishi, NestJS, Fastify. Our Cordis checkout installed 432 packages with 0 known vulnerabilities, but both build and test stopped within 10 seconds because the npm-created workspace state did not satisfy Yarn 4.

Setup2/5npm install passed, then Yarn rejected the workspace lock state
Docs3/5Useful English primer, but package READMEs are almost empty
Community4/5Aug 21 push plus active Aug 25 issues and pull requests
Maturity2/5No GitHub release and the README warns the API is unstable

Discussed on

  1. hnCordis – DeepSeek Harness Plugin Architecture [pdf]3 points

Who it’s for

Framework authors building a plugin host whose capabilities can be mounted and removed at runtime.
Agent-platform teams that need tools, model providers, sessions, and policies to register through shared service keys.
Applications that need dependency-aware activation rather than a hand-maintained plugin boot order.
Developers who need reload and teardown to reverse event listeners, adapters, timers, or other registered effects.

Who it’s NOT for

Application teams wanting a stable public API: the README says Cordis is under active development and may change without notice.
Developers expecting a self-contained product: the repository provides framework packages, while the clearest primer is written in the separate DeepSeek Harness documentation.
Projects whose standard install policy is npm-only: our npm install passed, but both project commands entered Yarn and rejected the resulting workspace lock state.
Teams that need published GitHub release notes for upgrade planning: the repository has no GitHub release yet.
Simple applications with a fixed startup graph: NestJS or Fastify will be more familiar if runtime plugin unloading and reversible effects are not requirements.

Setup reality

Our npm install succeeded in 120 seconds, adding 432 packages and using 145 MB on disk. The repository itself was tiny at 0.3 MB, 111 files, and about 8,440 source lines, so most of the local footprint came from dependencies. npm audit reported 0 known vulnerabilities.

Cordis itself needs no account or hosted service. Real use requires writing plugins, assigning service keys, declaring injected dependencies, and returning disposers for registered effects. The loader and HMR packages add configuration and reload behavior that application owners must test.

Build failed in 9 seconds and tests failed in 10 seconds. Both commands invoked Yarn 4.14.1 and reported that @root/cordis@workspace:. was absent from the lockfile, with advice to run yarn install. The log identifies a package-manager state mismatch; it shows no TypeScript error or failed test.

Cordis makes plugin registrations reversible

A Cordis context is a registry of services addressed by stable keys such as tools, model access, or sessions. Plugins ask for those services through declared injections rather than importing an implementation directly. If a required service is missing, activation waits. That turns boot order into a dependency relationship and lets a host add or remove a capability while the process stays alive.

The second idea is cleanup. Listeners, prompt fragments, provider adapters, timers, and other registrations can be installed as effects with matching disposers. When a plugin reloads or its context disappears, Cordis unwinds those registrations. The codebase is compact at about 8,440 lines in 111 files, yet it addresses a lifecycle problem that is easy to get wrong in a long-running agent or plugin host.

Four event modes make dispatch behavior explicit

Cordis documents four event modes. emit observes without waiting, parallel awaits listeners concurrently, and serial awaits them in registration order. waterfall behaves as around-middleware: a listener receives next, can delegate a changed value, or can stop the chain and own the result. The selected mode is part of an event's public contract.

That is more precise than one generic event emitter, but plugin authors have to choose correctly. A policy listener may intentionally short-circuit a waterfall; an observer that forgets next() can block everything downstream. Recent pull request #83 guarded waterfall continuation against double invocation, while pull request #81 addressed ordering for concurrent timer reads. The 49 open issues and pull requests on August 25 include real lifecycle edge cases, not only feature requests.

Services avoid concrete imports at the cost of indirection

A plugin claims a service key on its context, and consumers declare that key as an injected dependency. This makes implementations replaceable and allows a service to become available after startup. The linked primer recommends events for interception or policy and direct service methods for capability calls. That rule keeps cross-plugin behavior visible if a team follows it consistently.

Debugging can still become abstract. A missing capability may mean that no plugin registered it, its injection never activated, its fiber failed, or teardown removed it. Issue #95 reports a failed fiber re-entering reload during dependency refresh while retaining its error state. Cordis was pushed on August 21, 2026, and that issue was active on August 25, so maintenance is current even though the repository itself had no later push.

Loader and HMR target changing plugin graphs

The workspace includes core, loader, HMR, include, timer, logger, group, utility, and project-creation packages. Loader configuration can enable entries conditionally and interpolate configuration after declared injections activate. HMR then has to preserve the same dependency and disposal rules while code changes under a live process. This is where Cordis differs most from ordinary startup-only dependency injection.

The package READMEs barely explain those modules. packages/hmr/README.md and packages/loader/README.md contain little beyond their names. The useful explanation lives in the DeepSeek Harness primer and its English reference pages. That separation is a documentation cost for general adopters: the framework repository has 0 GitHub releases, and the best conceptual guide is framed around a downstream agent host.

What happened when we ran it

Our sandbox used npm to install 432 packages in 120 seconds at commit 8cc9e33. Dependencies occupied 145 MB, compared with a 0.3 MB checkout. npm audit found 0 known vulnerabilities across critical, high, moderate, and low severities. Installation completed, so the registry packages resolved in the fresh Node 22 container.

The build failed after 9 seconds. The root build script called yarn yakumo esbuild and yarn yakumo tsc, then Yarn 4.14.1 said @root/cordis@workspace:. did not appear in the lockfile. Its own message advised running yarn install to update that lockfile. No esbuild or TypeScript diagnostic appears because execution stopped during workspace resolution.

Tests failed after 10 seconds with the same lockfile message. The test script never produced a test count, assertion, or coverage result. On our box, mixing the npm install step with the project's Yarn command path created a state that Yarn rejected. The finding is narrower than a broken test suite, but it makes the correct package-manager workflow part of setup rather than an incidental preference.

The unstable API is a real adoption boundary

The main README has only 424 characters and explicitly warns that the API can change without notice. There is no latest GitHub release to anchor an upgrade policy. Recent work on unload registration, service callers, loader persistence, HMR, and event handling shows active development, while the lack of a release history makes compatibility harder to judge from tags.

Cordis deserves a prototype when a plugin host must react to services appearing and disappearing during its lifetime. Test failed activation, dependency refresh, repeated reload, partial teardown, and disposal order before trusting it. A fixed application graph does not need this machinery. NestJS is easier for conventional TypeScript services, and Fastify is more direct when the plugin surface is an HTTP server.

Alternatives

ProjectWhat it isPick it when
KoishiA larger TypeScript plugin framework and chatbot platform with context and service concepts.pick this instead when you want an application platform around the plugin model rather than only the underlying composition machinery.
NestJS gh↗A TypeScript server framework with dependency injection, modules, and a broad web ecosystem.pick this instead when conventional application modules and request handling matter more than live plugin teardown.
Fastify gh↗A Node.js web framework with encapsulated plugins and a mature HTTP focus.pick this instead when the plugins primarily add routes, hooks, and web-server capabilities.

What people are saying

  1. [github-trending] cordiverse/cordis

Sources

  1. Cordis README
  2. Cordis repository
  3. Cordis primer in English
  4. Failed fiber reload report #95
  5. Waterfall double-invocation fix #83

More dev tools reviews

Kaku · kordoc · hey · wechat-miniapp-radar · omarchy-workspace-layout · fermats-last-theorem · the whole board →