DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Safe Updater — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins
S

dsh-safe-updater

Safe Updater

通过配置文件冒烟测试和回滚机制,受控地自动更新 DeepSeek Harness。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add github:lucifer726/dsh-safe-updater#6e66f1d6ad14813dd0f59e7a37187cee75dbd3a4
README兼容性版本

兼容性与来源证明

Safe Updater 以 dsh-safe-updater 发布,当前版本为 0.1.0。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
any
发布来源
github
Registry 更新时间
2026/8/21

版本

0.1.0stable
2026/8/21

相关插件

正在加载相关插件…

最新版
0.1.0
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
未提供
文件数
未提供
Surface
any
许可证
MIT
发布源
github
GitHub
★ 0
周下载
0
最近提交
2026/8/21
查看源码 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

相关插件

继续浏览 developer-tools 分类下经过校验的插件。

Web App@deepseek-ai/dsh-web-appdsh 浏览器界面捆绑包:位于 dsh-base 之上的 Web 补丁层,加上运行时粘合插件(提供前端 dist、Web 界面提示符、bash 运行时变量和 URL 行)Sdk Minimal@deepseek-ai/dsh-sdk-minimal独立的最小 SDK 配置包:JSON-RPC、一个 DeepSeek 适配器、持久化 Shell 和 JSONL 会话Sdk App@deepseek-ai/dsh-sdk-appdsh SDK 配置包:基于 dsh-base 提供 stdio JSON-RPC 服务和进程生命周期管理Subagent Codex@deepseek-ai/dsh-subagent-codex基于官方 app-server 协议的一次性 Codex 子代理提供程序

README

dsh-safe-updater

Guarded updates for DeepSeek Harness. It checks npm releases, clones the selected profile into an isolated DSH_HOME, installs its dependencies, validates the composed config, starts a temporary Web server, and only then allows a supervised switch. Failed candidate health checks roll back to the previous version.

The default mode is notify. Installing this package does not silently replace a running Harness.

Install

dsh plugin --profile web add dsh-safe-updater

The bundle inserts the plugin with this safe default:

- insert:
    - id: safe-updater
      name: dsh-safe-updater
      config:
        mode: notify
        channel: latest
        profile: web
        checkIntervalMs: 21600000
        checkOnStart: true

Available plugin tools:

  • dsh_update_status: read current, available, staged, and rollback state.
  • dsh_update_check: check now; behavior follows the configured mode.

Modes

ModeBehavior
notifyCheck and record a newer release. Never install or restart.
stageClone the profile and run install, config, and HTTP smoke checks. Never restart.
applyStage, then request a switch from the external supervisor. Refused outside supervisor mode.

Supervisor and rollback

Run the Web profile under the updater when you want automatic activation:

dsh-safe-updater supervise \
  --version 0.1.1-rc.1 \
  --profile web \
  --host 127.0.0.1 \
  --port 3080

Then change the plugin's mode override to apply. When a staged candidate is ready, the plugin writes a version request. The supervisor starts that exact version with argv-based process spawning, waits for HTTP health, commits it, or returns to previousVersion.

Manual commands:

dsh-safe-updater check --current-version 0.1.1-rc.1
dsh-safe-updater stage --version 0.1.1-rc.1 --profile web
dsh-safe-updater status
dsh-safe-updater rollback

Trust and security model

  • Registry version strings are parsed as semantic versions and never executed as shell text.
  • Candidate commands use argument arrays with shell: false.
  • .credentials.yaml, sessions, workspaces, and other runtime data are never copied into staging.
  • State and locks are stored under ~/.dsh/safe-updater with restricted permissions and atomic replacement.
  • Smoke mode disables the updater timer to prevent recursive staging.
  • Update errors are logged and recorded; they do not interrupt the agent loop.

The selected profile's npm dependencies are still executable supply-chain inputs. Review and pin third-party plugins. Staging deliberately runs normal install scripts so native plugins are tested faithfully.

Publishing

GitHub Releases are the source and audit trail. npm is the installation channel. After configuring npm trusted publishing for this repository, set the GitHub Actions variable NPM_PUBLISH_ENABLED=true; tagged releases then publish with provenance via .github/workflows/publish.yml. Or publish locally after npm adduser:

npm publish --access public --provenance

License

MIT