
Research
/Security News
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.
@sonenta/realtime
Advanced tools
Realtime translation updates plugin for @sonenta/react-i18next (Centrifugo).
Realtime translation updates for Sonenta. A plugin
of your existing @sonenta/react-i18next provider: for dev versions it
subscribes to the version's Centrifugo channel and, when a new release is
published, bust-refetches the affected bundle and re-renders — no page
reload, no redeploy.
This was previously baked into @sonenta/react-i18next core; it was
extracted into this package in react-i18next 0.9.0 so realtime is opt-in
and the core stays lean.
@sonenta/realtime/react — the provider plugin (web/React).@sonenta/realtime/vue — the same plugin, for @sonenta/vue-i18n.@sonenta/realtime/svelte — the same plugin, for @sonenta/svelte-i18n.@sonenta/realtime/core — the framework-agnostic Centrifugo client
(LiveClient, fetchCentrifugoToken) for advanced/other-framework use.Unlike @sonenta/feedback and @sonenta/in-context, this package ships no
native entry point — it ships no UI at all, so it has no native view layer
to provide. That absence says what this package ships, not what it
runs on: nothing here is DOM-coupled, and LiveClient talks to Centrifugo
over a plain new WebSocket(url), which is a React Native global.
What has actually been tested (demo-app-expo, Expo 52 / RN 0.76.5 / Hermes, 2026-07-13):
@sonenta/realtime/react resolves under Metro with zero app-side config,
via the package root shim (Expo ships unstable_enablePackageExports off, so
the exports map is bypassed — which is exactly what the 0.1.1 shims were for).setup()
executes on-device.So on React Native the SDK resolves, runs, and executes its full startup path, including the conditional it is supposed to evaluate. The socket is unexercised because the product rule closed it, not because the platform blocked it.
Do not call this package "web only." That would assert a platform limitation that has now been positively disproven on a device. It is dev-only — which is a product decision, not a platform one, and true on every framework.
MIT.
npm i @sonenta/realtime
react and @sonenta/react-i18next (>= 0.9.0) are peer deps.
Add sonentaRealtime(...) to your i18n provider's plugins slot — no
second context, no extra config (it reuses the provider's apiBase /
projectUuid / token):
import { SonentaProvider } from "@sonenta/react-i18next";
import { sonentaRealtime } from "@sonenta/realtime/react";
<SonentaProvider
token="snt_live_…"
projectUuid="<project-uuid>"
defaultLocale="fr"
version="main"
plugins={[
sonentaRealtime({
wsUrl: "wss://rt.sonenta.dev/connection/websocket",
}),
]}
>
<App />
</SonentaProvider>;
sonentaRealtime accepts:
wsUrl (required) — the Centrifugo WebSocket URL.tokenEndpoint (optional) — defaults to
${apiBase}/v1/auth/centrifugo-token.Realtime is gated per version (Sonenta product model): on mount the
plugin reads the configured version's state from the backend
(GET /v1/projects/{id}/versions/{version} → is_dev + realtime_channel):
is_dev: true) — mints a version-scoped translations
token (POST /v1/auth/centrifugo-token { kind: "translations", version_uuid })
and subscribes to the version's realtime_channel.realtime_channel === null) — no subscription; a
console.warn explains realtime is dev-only, and bundles are served
statically from the CDN.This is independent of the provider's env flag (which only controls where
bundles are fetched). On each translations_published push for a
(language_code, namespace_slug) the app already loaded, the plugin calls
i18n.reload({ locale, namespace }) — a cache-bypassing refetch + re-render.
Connection + token minting are best-effort: a failure logs a console.warn
and the SDK keeps serving the last bundle. Teardown cancels any in-flight
setup and disposes the client.
FAQs
Realtime translation updates plugin for @sonenta/react-i18next (Centrifugo).
The npm package @sonenta/realtime receives a total of 22 weekly downloads. As such, @sonenta/realtime popularity was classified as not popular.
We found that @sonenta/realtime demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.