mrkeyoor.com_
Tue 29 Sept 06:37 UTC
Dev Toolsevaluationupdated 29 Sept 2026

yjs review

Yjs is a JavaScript library for shared documents whose concurrent edits merge without a central source of truth. It gives an app collaborative arrays, maps, text, and XML, while leaving networking and storage to separate providers.

Verdict

Our Yjs run installed 376 packages in 5 seconds and passed its tests in 17 seconds with 0 audit findings, making it easy to verify for teams prepared to build the surrounding sync service. Use it when offline merging, editor bindings, and transport choice matter more than getting one managed backend. Avoid feeding it untrusted updates without safeguards while issue 687 remains open.

We ran it

Lab card: what happened when we ran yjsScreenshot of yjs (docs.yjs.dev)
Install✓ · 5s376 packages · 96 MB
Buildn/ano build script
Tests✓ · 17sran, no count parsed
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo75 files~23,917 lines of source · 1.2 MB · 3 CI workflows · tests dir

Answers from our run

Does yjs build from source?

Dependencies installed in 5 seconds (376 packages), and the project has no separate build step. We cloned commit c286557 into a clean Debian container with 3 CPUs and no project-specific setup.

Do yjs's tests pass?

The test command failed in our container, and its output did not report a pass or fail count.

Does yjs have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use yjs?

Teams expecting one package to provide a hosted collaboration backend: the README says network functions and editor bindings live in separate modules.

What are the alternatives to yjs?

Automerge, Fluid Framework, Loro. Our Yjs run installed 376 packages in 5 seconds and passed its tests in 17 seconds with 0 audit findings, making it easy to verify for teams prepared to build the surrounding sync service.

Setup4/55-second install and passing tests, but providers are separate
Docs5/5Detailed APIs, provider choices, examples, and algorithm notes
Community5/522,859 stars, a September 2026 push, and active issue work
Maturity5/5Stable v13 line, active v14 work, and a broad integration catalog

Who it’s for

JavaScript teams adding multiplayer editing to a document, whiteboard, IDE, or structured workspace.
Local-first app developers who need offline changes to merge after clients reconnect.
Editor teams using ProseMirror, Tiptap, Monaco, CodeMirror, Quill, or another supported binding.
Engineers willing to choose and operate a transport, persistence layer, and access-control model around the core library.

Who it’s NOT for

Teams expecting one package to provide a hosted collaboration backend: the README says network functions and editor bindings live in separate modules.
Services that accept arbitrary binary updates from untrusted clients without resource limits: open issue 687 documents crafted updates that can loop forever or exhaust memory.
Projects pinned below Node 22 that plan to build the current main branch: its package manifest requires Node 22 or newer.
Operators seeking an official all-in-one container: our checkout had no Dockerfile, and the documented server, persistence, and authentication choices come from separate providers.

Setup reality

Our sandbox installed commit c286557 in 5 seconds, adding 376 packages and using 96 MB on disk. The repository has no build script, so there was no build step. Its tests passed in 17 seconds, and npm audit reported 0 known vulnerabilities.

The core library needs no credentials. The README's first networked example installs y-websocket, starts a server on port 1234, and leaves production transport, persistence, authentication, and any provider credentials to the provider you select.

The checked-out main branch requires Node 22 or newer and npm 8 or newer. It has no Dockerfile, and the optional V2 update format is not supported by every provider, so runtime packaging and wire-format compatibility need an explicit decision.

Four shared type families merge edits, while the server stays separate

Yjs exposes 4 shared type families: arrays, maps, text, and XML. They absorb concurrent edits and reach the same result. Each type can be observed like a local object, while document updates may arrive out of order or more than once. That is the useful abstraction: your editor code works with a document instead of resolving competing cursor positions by hand. Offline work can merge after a client reconnects.

The boundary is equally important. Yjs is network agnostic, so the core does not choose a server, database, identity system, or permission model. Release v13.6.33 is the latest stable GitHub release, while the current main branch identifies itself as a 14.0.0 release candidate. Adoption means choosing a mature merge engine plus an ecosystem of adapters instead of one prescribed collaboration stack.

A provider supplies the server and persistence Yjs leaves out

The README's 2-package quick start pairs Yjs with y-websocket, while its production guidance recommends a network provider plus a persistence provider. y-webrtc exchanges updates between peers, and y-indexeddb keeps browser state for faster local loading and offline work. Hosted and self-hosted alternatives add their own storage, authentication, webhooks, or operational model. This freedom is useful when collaboration must fit an existing product, but the architectural choice lands on your team.

The quick start installs yjs and y-websocket, then starts the sample WebSocket server on port 1234. No credential is required for the core library or that local example. A real deployment still needs an answer for who may join a document, where updates persist, how rooms are named, and what happens when a provider is unavailable. Those answers live outside this repository.

What happened when we ran it

We measured a 5-second install for commit c286557 in our sandbox. npm added 376 packages, and the installed tree occupied 96 MB. The supplied test command succeeded in 17 seconds. There was no build target named build, so we skipped that step instead of substituting another command. npm audit found 0 known vulnerabilities across the dependency tree.

The checkout itself was small: 75 files, about 23,917 lines of source, and 1.2 MB on disk. It included 3 CI workflow files and a tests directory, but no Dockerfile. The container had 3 CPUs, 8 GB of RAM, Node 22, no secrets, and no elevated privileges. These results verify installation and the repository's test path. They do not measure sync latency, document size, editor behavior, or performance under concurrent users.

Stable v13 releases and current issue work show active maintenance

GitHub recorded a push on September 29, 2026, and v13.6.33 was published six days earlier. That release fixed deep-observer event targeting and closed issue 768 through pull request 801. The repository also showed 22,859 stars and 138 open issues and pull requests. A new UndoManager bug report, issue 806, was opened on September 27, so the queue contains current user reports rather than only old residue.

Main is already on @y/y 14.0.0-rc.28 and requires Node 22 or newer, although the README's consumer command still installs yjs. That split deserves attention if you build from source, follow main, or maintain extensions against internal behavior. Most users should pin a published stable version and test their chosen editor binding and provider together rather than treating a passing core suite as proof of end-to-end compatibility.

Untrusted binary updates need limits while issue 687 is open

Yjs defines 2 binary update formats for document changes. Updates are commutative and idempotent, and state vectors let peers exchange only missing differences. The API can even merge or diff updates without loading a full document. Version 2 improves compression, but the README says it is not supported by every provider. Mixing formats or components therefore needs a compatibility check before rollout.

Open issue 687 reports malformed update buffers that can make merge or apply operations loop indefinitely or run out of memory. The report includes reproductions against Yjs 13.6.21 and remained open after an August 26, 2026 update. We did not reproduce that claim in our sandbox, and 0 npm audit findings do not settle it because an advisory scan is different from testing hostile input. Services accepting client updates should validate trust boundaries, isolate work, and enforce resource limits.

Editor bindings save integration work, but product behavior is still yours

Seven documented editor integrations include ProseMirror, Tiptap, Quill, CodeMirror, Monaco, Lexical, and Slate, with more listed in the README. Yjs also provides relative positions, snapshots, and an UndoManager, while providers can carry cursor awareness. Those pieces remove a large amount of low-level collaboration work. They do not decide how comments attach to changing text, which actions share an undo history, or how a user recovers from a rejected update.

Storage needs the same care. The README explains that text-oriented CRDTs grow as edits accumulate, then describes how Yjs merges adjacent structures, removes deleted content, and garbage-collects some tombstones. Setting doc.gc to false preserves information needed to restore old content, with a storage cost. Before committing, test the documents you actually keep, over the retention window you actually promise. Our 17-second suite says the core passed; your provider, editor, access rules, and history policy decide whether the product does.

Alternatives

ProjectWhat it isPick it when
AutomergeA JSON-like CRDT library with JavaScript and Rust implementations.pick this instead when a JSON document model and Automerge's storage and sync stack fit your application better.
Fluid FrameworkMicrosoft's framework for distributed, real-time collaborative web applications.pick this instead when you want a broader collaboration framework with its own container and service concepts.
LoroA Rust-based CRDT library for collaborative, version-controlled JSON data.pick this instead when Rust, explicit version history, or Loro's data model is the better foundation.

What people are saying

  1. [velocity-scout] yjs/yjs

Sources

  1. Yjs repository and README
  2. Yjs package manifest on main
  3. Yjs v13.6.33 release
  4. Issue 687: crafted update denial of service report
  5. Issue 806: UndoManager restoration report

More dev tools reviews

omarchy-workspace-layout · fermats-last-theorem · ffuf · ipadecrypt · coursebook · ink · the whole board →