dsh-release-proof
A DeepSeek Harness tool plugin for generating deterministic, multi-source release verification evidence.
Install
$ dsh plugin --profile web add github:dongsheng123132/dsh-release-proofPlugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Registers DSH tools to inspect release manifests and verify declared sources.
- Downloads every manifest-declared mirror for an artifact and checks status, advertised and actual size, SHA-256, and release version.
- Writes deterministic, content-addressed JSON evidence after verification.
- Provides a standalone stdio MCP server and a CLI for inspection and verification.
- Applies anonymous-HTTP(S) restrictions, bounded request limits, source concurrency limits, and workspace-relative output-path protections.
Useful For
- Confirm that mirrored release endpoints serve matching artifacts before publishing or distributing a release.
- Produce reproducible evidence for release checks in CI or release engineering workflows.
- Inspect a release manifest without exposing source URLs through the DSH inspection tool.
- Run release-source verification through DSH, MCP, or the command line.
Who It Fits
- Release engineers
- Software supply-chain and security teams
- DeepSeek Harness users managing artifact mirrors
- CI/CD maintainers
Documented Limitations
- Only validates values declared in the manifest; expected version, byte size, and SHA-256 must be supplied.
- Does not prove publisher identity or verify signed release attestations.
- Requires at least two sources for each artifact.
- DSH plugin and CLI usage require Node.js 22 or newer.
- MCP accepts inline manifest JSON up to 1 MiB and does not read or write the filesystem.
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 0 runtime, 1 development, 1 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- dongsheng123132/dsh-release-proof
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin
- Source checked
- 1c6ef06 · 2026-09-14
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 2GitHub stars
- Forks
- 0
- Open issues
- 0
- Last commit
- 2026-09-07
- Last release
- No release detected
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
Vision routing and pixel-level visual tool suite for DeepSeek Harness agents with built-in free fallbacks.
View plugin →Image generation and iterative editing plugin for DeepSeek Harness supporting cloud providers and local ComfyUI.
View plugin →Browser automation plugin enabling DeepSeek Harness agents to interact with logged-in browser sessions safely via dedicated Agent Windows.
View plugin →DeepSeek Harness research bundle for industry maps, public-source tracking, company cards, and traceable reports.
View plugin →