← DeepSeek Harness Plugins
DeepSeek Harness PluginManifest Valid

dsh-release-proof

A DeepSeek Harness tool plugin for generating deterministic, multi-source release verification evidence.

Developer ToolsSkills & Workflows
2GitHub Stars0ForksUpdated2026-09-07

Install

$ dsh plugin --profile web add github:dongsheng123132/dsh-release-proof

Plugin Overview & Capabilities

AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.

source-grounded
dsh-release-proof verifies release artifacts across manifest-declared mirrors, checking HTTP status, byte length, SHA-256, and version before writing a content-addressed JSON proof artifact.

Key Capabilities

  • Registers DSH tools to inspect release manifests and verify declared sources.
  • Downloads every manifest-declared mirror for an artifact and checks status, advertised and actual size, SHA-256, and release version.
  • Writes deterministic, content-addressed JSON evidence after verification.
  • Provides a standalone stdio MCP server and a CLI for inspection and verification.
  • Applies anonymous-HTTP(S) restrictions, bounded request limits, source concurrency limits, and workspace-relative output-path protections.

Useful For

  • Confirm that mirrored release endpoints serve matching artifacts before publishing or distributing a release.
  • Produce reproducible evidence for release checks in CI or release engineering workflows.
  • Inspect a release manifest without exposing source URLs through the DSH inspection tool.
  • Run release-source verification through DSH, MCP, or the command line.

Who It Fits

  • Release engineers
  • Software supply-chain and security teams
  • DeepSeek Harness users managing artifact mirrors
  • CI/CD maintainers

Documented Limitations

  • Only validates values declared in the manifest; expected version, byte size, and SHA-256 must be supplied.
  • Does not prove publisher identity or verify signed release attestations.
  • Requires at least two sources for each artifact.
  • DSH plugin and CLI usage require Node.js 22 or newer.
  • MCP accepts inline manifest JSON up to 1 MiB and does not read or write the filesystem.

DSH Compatibility

Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.

Not tested yetNo runtime compatibility tests have been published yet.

Security Signals

Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.

Dependency Counts

package.json declares 0 runtime, 1 development, 1 peer, and 0 optional dependencies.

info
Dsh Bundle Declared

package.json declares DSH bundle metadata.

info
License Declared

GitHub reports the repository license as MIT.

info
Package Manifest Available

A root package.json was captured and can be inspected by the registry.

info
Source Available

Public GitHub source metadata is available for this registry snapshot.

info

Source & Registry Notes

Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.

Source repository
dongsheng123132/dsh-release-proof
Registry source
GitHub · dsh-plugin topic
Registry classification
Plugin
Source checked
1c6ef06 · 2026-09-14

This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.

Repository Activity

GitHub stars
2GitHub stars
Forks
0
Open issues
0
Last commit
2026-09-07
Last release
No release detected
For maintainers

Maintaining this plugin?

This listing is generated from public repository data. If you maintain this project, you can review the information and share this listing with your users if you find it useful.

Add to README
Listed on DSHPlugin.app