DeepSeek Harness 一周更新汇总:v0.1.5 正式定档,v0.1.6 带着八个新入口杀到DSH Weekly Update Roundup: v0.1.5 Locks In, v0.1.6 Arrives With Eight New Entry Points

站内动态10 分钟阅读更新于 2026 年 9 月 19 日

GitHub 上 deepseek-ai/deepseek-harness 仓库的发布记录显示,9 月 8 日到 9 月 15 日这 8 天里连发了 7 个版本:

◆知微•站内动态 · 10 分钟阅读 · 2026 年 9 月 19 日
Site Update10 min readUpdated September 19, 2026

The release history of the deepseek-ai/deepseek-harness repository on GitHub shows 7 versions shipped in the 8 days from September 8 to September 15:

◆知微•Site Update · 10 min read · September 19, 2026
DeepSeek Harness 一周更新汇总:v0.1.5 正式定档,v0.1.6 带着八个新入口杀到

这一周 DSH 更新得很密:9 月 10 日 v0.1.5-rc.2 定稿,模型和外壳第一次「一起进化」;9 月 15 日 v0.1.6-alpha.1 给 Agent 发了一堆「手」,两天后 alpha.2 又给用户装上「控制台」;源码里还藏着个正在内测的官方桌面端。一周 7 个版本,节奏快得像赶工,其实每一步都有迹可循。

先看这一周的发布节奏

GitHub 上 deepseek-ai/deepseek-harness 仓库的发布记录显示,9 月 8 日到 9 月 15 日这 8 天里连发了 7 个版本:

  • 9 月 8 日 v0.1.5-alpha.1
  • 9 月 9 日 v0.1.5-alpha.2
  • 9 月 10 日 v0.1.5-rc.1 与 v0.1.5-rc.2(一日双发)
  • 9 月 15 日 v0.1.6-alpha.1
  • 9 月 17 日 v0.1.6-alpha.2

rc.1 和 rc.2 是一天里的两连发,分工很清楚:rc.1 汇总了 alpha 阶段的模型适配与 UI 能力(V4.1 Flash 成为新会话默认模型),rc.2 只补了一条体验优化——反馈提交改成弹窗确认,失败时保留已填内容。前者是「正式版的内容冻结」,后者是发布前的收尾打磨,两天后 0.1.5 正式定档。

按 releasealert 统计,这个仓库 8 月 17 日以来已发布 17 个版本,平均 1 天 18 小时一个。这种节奏在 0.1.x 阶段并不常见。

v0.1.5:模型和外壳开始「一起进化」

配图

v0.1.5 的核心是 DeepSeek V4.1 Flash 的深度适配。官方公告的说法是:模型在 Harness 的不同配置中都进行了专项训练和优化。这句话值得展开一下——按媒体拆解,训练覆盖了三种 Harness 配置:

  • 标准模式:完整工具、Skills、文件、Shell、任务规划,日常用的完整形态
  • PTC 模式:程序化工具调用。模型不是「调一个工具、等结果、再想」,而是一次生成一段代码,把多轮工具调用组织起来批量跑
  • 极简模式:把外壳压到最轻,只留终端和文件编辑,看模型自己能干多少

以前是先训完模型,再套个 Agent 框架试试能不能用;现在模型训练阶段就把 Harness 的形态考虑进去,两边共同进化。这也和 DeepSeek 一直强调的「Agent = Model + Harness」对上了。

v0.1.5 还有一个很工程的细节:更新系统提示词时尽量保留 KV Cache。长程 Agent 任务里,中途改一条规则不用把后面一大段上下文重新算一遍。对普通聊天感知不明显,对跑长任务的用户是实打实的提速。

UI 侧同步补了一批能力:Web 界面支持上传图片和 PDF,模型通过专门的文件工具按需读取;右侧边栏支持 Markdown、HTML、PDF、图片和常见代码格式的原生预览;插件作者拿到了标准化的扩展入口——左侧栏可注册全局入口点,右侧栏支持自定义标签页,可多标签、分屏、全屏。

配套开源的还有实验性 Agent Teams:父子 Agent 双向通信,主 Agent 可以给不同子 Agent 指定不同的模型和推理强度,结果由主 Agent 汇总。

v0.1.6-alpha.1:八个新入口,Agent 的「手」变多了

9 月 15 日的 v0.1.6-alpha.1,对比 v0.1.5-rc.2 相差约 800 个提交(含功能、修复、测试与合并记录,不等于 800 个功能)。八项重点:

  • Browser Use:接入 Playwright MCP、Chrome DevTools MCP、Stagehand 三套实验性后端,Agent 可以做点击、输入、导航等真实网页操作。支持 launch 新浏览器或 attach 已有浏览器(attach 需配置调试端点,才能用上已有标签页和登录状态)
  • Computer Use:Cua Driver 的 MCP 与原生两条实验路线,用于本机操作和截图,需显式配置
  • SSH 远程工作区:本地 Harness 保留模型调用、权限管理、Session 持久化,通过 SSH 用远端的文件、进程和执行环境。初始范围是 POSIX 环境下的 Headless 与自定义配置组合,需准备远端辅助程序
  • Web Terminal:网页侧边栏新增终端,支持多标签、Shell 选择、页面刷新后恢复
  • Headless 增强:新增 stdin 任务接入、--session-id 续接已有会话、--json 逐行输出运行事件,外部程序终于能「看懂」DSH 正在干什么
  • MCP 资源能力:支持资源发现、资源读取与 URI Template,区分「执行动作」与「读取内容」
  • 归档会话恢复:设置里新增已归档会话列表,可查看、可恢复
  • 实验性 Auto Review:工具调用执行前由当前 Agent 的模型自动审查,允许或拒绝。注意每次审查都会额外产生模型请求

有几个边界得说清楚。Browser Use 和 Computer Use 都是默认不启用的可选组件;attach 模式「保留登录状态」有前提,不是随便一个浏览器就能接管。Auto Review 获准的调用以完全访问执行,没有文件沙箱,模型也可能误放行或误拒绝,谈不上无人值守的安全保证。取消任务也不等于撤销操作,已经送出去的点击和输入不会自动恢复原状。JSON 事件流里正文和推理是步骤提交后输出,不是逐 token 实时,自动化程序应检查退出码与轮次结束原因,不能看到 final 就当成功。

配置层面也有几处会影响旧环境的变化:DeepSeek 适配器默认改用 Messages 协议,手动覆盖过旧官方根地址的用户需要按说明调整;Ralph 默认关闭,内置 E2B 后端移除,PTC 包和服务统一到 ptc-runtime 系列;实验性 Team 模式统一用 spawn_teammate,默认队友创建上限从 8 提到 16;Node PTC 改为独立进程执行,process.env 为空,依赖环境变量的 PTC 代码要重新检查。

v0.1.6-alpha.2:给用户装上「控制台」

9 月 17 日的 alpha.2 是个「插件 + 界面」主题的版本,官方发布说明 6 组 33 条。如果说 alpha.1 让 Agent 能操作浏览器和电脑,这一版就是让人能管住它们:

  • 插件管理页:安装、改配置、实时启停,插件生态从命令行搬进了界面
  • 文件改动卡片:会话每轮结束时列出改了哪些文件,侧边栏里逐文件对比审阅
  • 侧边栏预览 Office 文件:Word、Excel、PowerPoint 都能直接看
  • 侧边栏浏览器模式:指定 URL 在侧边栏打开
  • 侧边栏打开 Subagent 会话、预览提交计划

体验侧的升级密集但琐碎:侧边栏布局持久化、刷新后终端保持连接;首条消息发出前就能用文件预览和终端;上下文用量移到输入框底部,点开看明细;CLI 和 Web 启动提速。修复里值得点名的是 Messages API 地址拼接的修补(上一切换协议的后续)和 Windows 跑 PTC、Shell 命令时控制台窗口闪现的老毛病。

开发者要注意三条破坏性变更:插件依赖改成运行时解析、支持运行时卸载,加载和卸载逻辑要重查;创造模式移除 Cordis 动态定义工具,改走 Plugin Manager 装持久化插件;客户端 Session 支持多实例共存,相关 API 和 slot 有变化。另外默认模型列表移除了 V4 Flash 和 V4 Flash Vision Exp——结合 rc.1 里 V4.1 Flash 成为默认,模型线正在明显收敛。Subagent 链也加了默认上限:同时最多 8 个子代理、委派深度 1,可在设置里调。

源码里的彩蛋:官方桌面端已经在内测

翻仓库源码,apps 目录下除了 cli 和 web,还多了 desktop 和 desktop-host 两个目录。官方桌面端不是传闻,是已经在仓库里的现实。

README 写得很坦白:DeepSeek Harness Desktop 是一个 Electron 薄封装,完整复用 Web 应用的行为,只做平台适配。几个关键信息:

  • 平台支持 macOS(arm64 与 x64)和 Windows x64,Linux 明确不在发布目标里
  • 内置独立运行时:自带 Python、Node.js、pnpm 发行版,Python 预装 numpy、pandas、python-docx、python-pptx、openpyxl、Pillow、lxml、XlsxWriter,首次使用离线装到用户目录——开箱即用的 Office 文档处理
  • 默认注册 office-docx、office-pptx、office-xlsx 三个技能
  • 与 CLI 共享会话、设置、凭证、工作区,但可执行状态完全隔离,桌面独占一个 profile
  • 自动更新走 Nightly 通道,10 分钟间隔异步检查,支持强制更新策略
  • Windows 用 EV 证书签名加 NSIS 安装器,macOS 做公证、DMG 与 ZIP 双通道

从提交记录看,9 月 11 日到 17 日桌面端相关提交密集落地:图标设计、Windows 安装器打包、版本号已推进到 0.1.6-alpha.2 同款。README 里出现了「早期内测包」「internal-test packaging」的表述,更新通道固定为 Nightly——阶段很清楚:官方桌面端已在内测,还没公开发布。对不想配环境的用户来说,这可能是比任何单点功能都重要的变化。

一个值得升级前看一眼的开关

v0.1.6 在 DeepSeek 适配器请求路径中默认启用了会话日志贡献器,通过 dsh_session_log 字段发送尚未确认接收的会话事件,内容可能包含消息文本、工具参数与结果、工作区路径和反馈。

官方说明这个字段不加入模型的 messages,不占模型输入 token,也不改变模型可见的缓存前缀;但内容仍会随 HTTP 请求发出去。不占 token 和数据留在本机是两回事。

不想启用的用户可以显式关闭:新建 privacy.patch.yml 写入对应条目,先用 --dump-config 确认配置生效,再带同一份补丁启动。还要注意这条日志链与 OTel 遥测相互独立,关一个不等于关另一个。

怎么看这一周的更新

一周 7 个版本,三条线索很清楚:纵向上,模型和外壳从「各自迭代」走向「一起训练」,V4.1 Flash 对三种 Harness 配置做专项优化是标志性的一步;横向上,Agent 的执行入口从文件和命令,扩到浏览器、桌面、远程服务器,Headless 又把这套能力交给脚本和流水线;第三条藏在源码里——桌面端、插件管理页、Office 预览一起指向同一个方向:DSH 想做的不是一根命令行管道,而是一个完整的开发工作台。

v0.1.6 系列还是 Alpha 预发布,功能列表上的「已加入」和日常使用的「已成熟」是两个阶段。几条实操顺序建议:先试 Web Terminal、归档恢复、Headless 这类低风险项;浏览器和本机操作先用独立的测试浏览器、可丢弃的测试项目验证;Auto Review 放最后,先看清权限与成本。插件作者升级前优先核对依赖解析和 Session API 两条破坏性变更。升级前备份 DSH Home,重要环境留好退路。

安全提醒:DSH 相关能力仅限授权场景使用,涉及浏览器登录态、远程服务器与本机桌面操作时,务必确认自己有相应权限,勿用于任何非法行为。

本文信息截至 2026 年 9 月 19 日。版本信息据 GitHub 官方发布记录(v0.1.5-rc.1 / rc.2、v0.1.6-alpha.1 / alpha.2 发布说明及仓库源码),个别细节以官方发布说明为准。

DSH updated densely this week: v0.1.5-rc.2 was finalized on September 10, the first time the model and the shell "evolved together"; on September 15, v0.1.6-alpha.1 handed the Agent a pile of new "hands," and two days later alpha.2 fitted users with a "console"; and hidden in the source is an official desktop app already in internal testing. Seven versions in one week—a pace that looks like a rush, when in fact every step is traceable.

First, this week's release cadence

配图

The release history of the deepseek-ai/deepseek-harness repository on GitHub shows 7 versions shipped in the 8 days from September 8 to September 15:

  • September 8: v0.1.5-alpha.1
  • September 9: v0.1.5-alpha.2
  • September 10: v0.1.5-rc.1 and v0.1.5-rc.2 (two in one day)
  • September 15: v0.1.6-alpha.1
  • September 17: v0.1.6-alpha.2

rc.1 and rc.2 landed back to back on the same day with a clear division of labor: rc.1 collected the model adaptations and UI capabilities from the alpha phase (V4.1 Flash became the default model for new sessions), while rc.2 added just one experience improvement—feedback submission now uses a confirmation dialog and preserves what you've filled in if it fails. The former is the "content freeze for the stable release," the latter the final polish before shipping, and two days later 0.1.5 was locked in.

According to releasealert, the repository has published 17 versions since August 17, averaging one every 1 day 18 hours. That cadence is unusual for the 0.1.x stage.

v0.1.5: the model and the shell start to "evolve together"

配图

The core of v0.1.5 is deep adaptation for DeepSeek V4.1 Flash. In the official announcement's words: the model was specially trained and optimized across different Harness configurations. That sentence deserves unpacking—according to media breakdowns, training covered three Harness configurations:

  • Standard mode: the full set of tools, Skills, files, Shell, and task planning—the complete form you use day to day
  • PTC mode: programmatic tool calling. The model doesn't "call one tool, wait for the result, then think again"; it generates a block of code at once and orchestrates multiple rounds of tool calls to run in batches
  • Minimal mode: the shell stripped down as far as possible, leaving only the terminal and file editing, to see how much the model can do on its own

It used to be that you trained the model first, then wrapped an Agent framework around it to see whether it worked; now the shape of the Harness is taken into account during model training, and the two sides co-evolve. That also lines up with DeepSeek's long-standing framing: "Agent = Model + Harness."

v0.1.5 also has a very engineering-flavored detail: preserve the KV Cache as much as possible when updating the system prompt. In long-horizon Agent tasks, changing a rule midway doesn't force a large stretch of downstream context to be recomputed. Ordinary chat won't notice, but for users running long tasks it's a real speedup.

The UI side gained a batch of capabilities at the same time: the Web interface supports uploading images and PDFs, which the model reads on demand through dedicated file tools; the right sidebar natively previews Markdown, HTML, PDF, images, and common code formats; and plugin authors got standardized extension points—the left sidebar can register global entry points, while the right sidebar supports custom tabs with multiple tabs, split screen, and full screen.

Also open-sourced alongside is experimental Agent Teams: parent and child Agents communicate in both directions, the main Agent can assign different models and reasoning efforts to different subagents, and the main Agent aggregates the results.

v0.1.6-alpha.1: eight new entry points, and more "hands" for the Agent

v0.1.6-alpha.1 on September 15 differs from v0.1.5-rc.2 by about 800 commits (including features, fixes, tests, and merge records—not the same as 800 features). Eight highlights:

  • Browser Use: integrates three experimental backends—Playwright MCP, Chrome DevTools MCP, and Stagehand—so the Agent can perform real web actions like clicking, typing, and navigating. It supports launching a new browser or attaching to an existing one (attach requires configuring a debug endpoint before you can use existing tabs and login state)
  • Computer Use: two experimental paths, Cua Driver's MCP and native, for local machine operations and screenshots, requiring explicit configuration
  • SSH remote workspace: the local Harness keeps model calls, permission management, and Session persistence, while using the remote machine's files, processes, and execution environment over SSH. The initial scope is Headless and custom-configuration combinations in POSIX environments, and it requires preparing a remote helper program
  • Web Terminal: a new terminal in the web sidebar, with multiple tabs, shell selection, and restoration after a page refresh
  • Headless enhancements: new stdin task intake, --session-id to continue an existing session, and --json to emit run events line by line—external programs can finally "understand" what DSH is doing
  • MCP resource capabilities: support for resource discovery, resource reading, and URI Templates, distinguishing "performing an action" from "reading content"
  • Archived session recovery: a new list of archived sessions in settings, viewable and restorable
  • Experimental Auto Review: tool calls are automatically reviewed by the current Agent's model before execution and allowed or denied. Note that every review generates an additional model request

A few boundaries need to be stated clearly. Browser Use and Computer Use are both optional components that are disabled by default; the "preserves login state" claim for attach mode comes with preconditions—not just any browser can be taken over. Auto Review approves calls that then execute with full access, with no file sandbox, and the model may also wrongly allow or wrongly deny, so there is no question of an unattended safety guarantee. Canceling a task is also not the same as undoing an action: clicks and keystrokes already sent out will not automatically revert. In the JSON event stream, body text and reasoning are emitted after a step is submitted, not token by token in real time, so automation programs should check the exit code and the reason the turn ended—seeing final does not mean success.

There are also several configuration-level changes that will affect existing environments: the DeepSeek adapter now defaults to the Messages protocol, so users who manually overrode the old official base URL need to adjust it as documented; Ralph is off by default, the built-in E2B backend is removed, and the PTC package and services are unified under the ptc-runtime series; experimental Team mode uniformly uses spawn_teammate, and the default teammate creation limit rises from 8 to 16; Node PTC now executes in a separate process with an empty process.env, so PTC code that depends on environment variables needs to be rechecked.

v0.1.6-alpha.2: fitting users with a "console"

alpha.2 on September 17 is a "plugins + interface" themed release, with 6 groups and 33 items in the official release notes. If alpha.1 let the Agent operate browsers and computers, this version is about letting people keep them under control:

  • Plugin management page: install, change configuration, and start/stop in real time—the plugin ecosystem moves from the command line into the interface
  • File change cards: at the end of each session turn, list which files were changed, with per-file diff review in the sidebar
  • Sidebar preview of Office files: Word, Excel, and PowerPoint can all be viewed directly
  • Sidebar browser mode: open a specified URL in the sidebar
  • Open Subagent sessions and preview the submission plan in the sidebar

The experience-side upgrades are dense but small: sidebar layout persistence and terminals that stay connected after a refresh; file preview and terminal available before the first message is sent; context usage moved to the bottom of the input box, expandable for details; faster CLI and Web startup. Among the fixes, two are worth naming: the repair of Messages API URL concatenation (follow-up to the earlier protocol switch) and the long-standing issue of console windows flashing when running PTC and Shell commands on Windows.

Developers should note three breaking changes: plugin dependencies are now resolved at runtime and support runtime uninstall, so loading and unloading logic needs rechecking; creation mode removes Cordis dynamic tool definition in favor of installing persistent plugins through Plugin Manager; and client Sessions support multiple coexisting instances, with related APIs and slots changed. In addition, the default model list drops V4 Flash and V4 Flash Vision Exp—combined with V4.1 Flash becoming the default in rc.1, the model line is clearly converging. The Subagent chain also gained default limits: at most 8 subagents at once and a delegation depth of 1, adjustable in settings.

An easter egg in the source: the official desktop app is already in internal testing

Digging through the repository source, the apps directory now contains desktop and desktop-host alongside cli and web. The official desktop app isn't a rumor—it's already a reality in the repository.

The README is candid: DeepSeek Harness Desktop is a thin Electron wrapper that fully reuses the Web app's behavior and only handles platform adaptation. A few key details:

  • Platform support covers macOS (arm64 and x64) and Windows x64; Linux is explicitly not a release target
  • A bundled standalone runtime: it ships its own Python, Node.js, and pnpm distributions, with Python preloaded with numpy, pandas, python-docx, python-pptx, openpyxl, Pillow, lxml, and XlsxWriter, installed offline into the user directory on first use—Office document handling that works out of the box
  • Three skills registered by default: office-docx, office-pptx, office-xlsx
  • It shares sessions, settings, credentials, and workspaces with the CLI, but executable state is fully isolated, with the desktop getting a profile of its own
  • Auto-update runs on the Nightly channel, checking asynchronously every 10 minutes, with support for forced-update policies
  • Windows uses EV certificate signing plus an NSIS installer; macOS gets notarization with dual DMG and ZIP channels

Judging by the commit history, desktop-related commits landed densely from September 11 to 17: icon design, Windows installer packaging, and a version number already advanced to match 0.1.6-alpha.2. The README uses phrases like "early internal test build" and "internal-test packaging," with the update channel fixed to Nightly—so the stage is clear: the official desktop app is in internal testing, not yet publicly released. For users who don't want to set up an environment, this may matter more than any single feature.

A switch worth a look before upgrading

In v0.1.6, a session log contributor is enabled by default in the DeepSeek adapter request path, sending not-yet-acknowledged session events through the dsh_session_log field. The content may include message text, tool arguments and results, workspace paths, and feedback.

The official explanation is that this field is not added to the model's messages, does not consume model input tokens, and does not change the cache prefix visible to the model; but the content is still sent out with the HTTP request. Not consuming tokens and staying on your own machine are two different things.

Users who don't want it enabled can turn it off explicitly: create privacy.patch.yml and write in the corresponding entry, first use --dump-config to confirm the configuration takes effect, then start with the same patch. Also note that this logging chain is independent of OTel telemetry—turning off one does not turn off the other.

How to read this week's updates

Seven versions in a week, and three threads are clear. Vertically, the model and the shell moved from "iterating separately" to "training together," with V4.1 Flash's dedicated optimization for three Harness configurations as the landmark step. Horizontally, the Agent's execution entry points expanded from files and commands to browsers, the desktop, and remote servers, while Headless hands that whole capability set to scripts and pipelines. The third thread is hidden in the source—the desktop app, the plugin management page, and Office preview all point the same direction: what DSH wants to be isn't a command-line pipe but a complete development workbench.

The v0.1.6 series is still an Alpha prerelease, and "added to the feature list" and "mature enough for daily use" are two different stages. A few practical ordering suggestions: start with low-risk items like Web Terminal, archived session recovery, and Headless; validate browser and local machine operations first with a separate test browser and a disposable test project; leave Auto Review for last, after you've seen its permissions and costs clearly. Plugin authors should check the two breaking changes—dependency resolution and the Session API—before upgrading. Back up DSH Home before upgrading, and keep a way back for important environments.

Safety note: DSH-related capabilities are for authorized scenarios only. When browser login state, remote servers, and local desktop operations are involved, be sure you have the appropriate permissions, and do not use them for any illegal purpose.

This article's information is current as of September 19, 2026. Version information is based on GitHub's official release records (the v0.1.5-rc.1 / rc.2 and v0.1.6-alpha.1 / alpha.2 release notes and the repository source); for individual details, defer to the official release notes.