Apageoflove/DSH-changeproof 预览 preview

Apageoflove/DSH-changeproof

DeepSeek Harness 插件:确认改动的代码行真的被测试覆盖到,结论绑定代码指纹,代码一变自动过期

Project Overview项目介绍

DSH-changeproof is a native plugin built exclusively for DeepSeek Harness (DSH) that verifies whether changed lines of code are actually covered by tests after code modification. It addresses three common issues that can lead to false green test results: tests passing for unrelated files, only partial changed lines being executed, and stale verification results persisting after new changes. It delivers three core functions to solve these problems: matching relevant tests to changes, line-by-line coverage checking after test execution, and automatic detection of stale verification results. It outputs six possible verification statuses and enforces a strict rule that no change gets a verified passing status without valid coverage evidence.

To install the plugin, you first clone the DeepSeek Harness source code from GitHub or Gitee, then build DSH's core libraries and optionally its web user interface. After that, you clone this plugin repository, install its dependencies with npm, build the plugin output, then add the local plugin directory to your DSH profile using DSH's built-in plugin CLI command. Once installed, you can run DSH in either web GUI mode or headless CLI mode, and verification runs automatically after the model modifies code, so no manual trigger is required for normal use.

The plugin can also be used standalone without installing DSH, via its own command line interface that lets you plan changes, run full verification, and check the current status of past verification results. It requires Node.js 24 or newer to build and run, and works with Jest, Vitest, and Pytest test frameworks through their standard Istanbul or coverage.py output formats. It is released under the permissive MIT open source license, and includes multiple security hardening features for executing test commands, including argv-only execution, path validation, and full process tree cleanup on timeout.

DSH-changeproof 是专为 DeepSeek Harness (DSH) 开发的原生插件,核心功能是在代码改动后验证改动行是否真的被测试覆盖。它解决了测试全绿但改动未被覆盖、部分改动行未执行、代码变更后旧验证结论仍生效的常见问题,提供关联测试匹配、行级覆盖核对、结论过期检测三项核心能力,输出六种验证状态,严格保证没有有效覆盖证据就不会通过验证。

安装需要先获取并构建 DSH 源码,再构建本插件后通过 DSH 的插件命令添加到对应运行配置(profile),同时支持 web 图形界面和 headless 命令行两种模式,模型修改代码后会自动调用验证,无需手动触发。也可以脱离 DSH 独立使用,提供独立命令行接口供用户分析改动、执行验证和检查结论状态。

项目依赖 Node.js ≥ 24,使用 pnpm 构建,采用 MIT 许可证开源。架构上核心逻辑与 DSH 绑定层分离,核心无 DSH 依赖,支持 Jest、Vitest、Pytest 三种测试框架的覆盖率解析,内置多重执行安全加固,防止测试命令执行时的路径逃逸等安全风险。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 5 stars - very few users, little community feedback星标只有 5,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:Apageoflove/DSH-changeproof

把 Apageoflove/DSH-changeproof 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

DSH-changeproof(变更证明 ChangeProof)

DeepSeek Harness(DSH)插件:代码改动后,确认改动的行真的被测试覆盖到。

解决的问题

"测试通过"不等于"改动被验证":

  • 改的是 A 文件,测试跑的是 B 文件,全绿但改动没被测到;
  • 测试跑了,但只执行到改动行的一部分,剩余行没测到,照样报通过;
  • 验证完成后代码又被修改,旧结论仍然有效,无人察觉。

插件做三件事:

  1. 关联测试:根据代码引用关系,找出与本次改动相关的测试(不是全量跑,也不是猜);
  2. 行级核对:执行测试后逐行核对,改动行未被执行到则不予通过,并明确指出未覆盖的行;
  3. 结论过期:证据绑定代码指纹,代码一变,旧结论自动失效。

结论状态:VERIFIED(通过)、PARTIAL(部分覆盖)、FAILED(测试失败)、STALE(结论过期)、UNVERIFIED(无有效证据)、NOT_APPLICABLE(无可验证内容)。

底线:没有覆盖证据,或证据与当前代码不一致,一律不给 VERIFIED。

部署到 DSH

以下步骤在 Windows 实测通过(macOS / Linux 命令相同)。

前提

  • Node.js ≥ 24(DSH 要求 ^22.19 || >=24)
  • pnpm 11.7(npm install -g pnpm@11.7.0)
  • Git

1. 获取 DSH 源码

git clone --depth 1 https://gitee.com/mirrors/deepseek-harness.git DSH
# GitHub 直连:git clone --depth 1 https://github.com/deepseek-ai/deepseek-harness.git DSH
cd DSH

2. 构建 DSH

pnpm install
pnpm run build:lib
pnpm run build:web   # 仅使用 headless 可跳过

3. 构建插件

cd <插件目录>        # 如 E:\agent\dsh-changeproof
npm install
npm run build        # 产物在 dist/

4. 安装到 profile

cd <DSH 目录>
pnpm dsh plugin --profile web add <插件目录>
# 需要命令行模式再加:pnpm dsh plugin --profile headless add <插件目录>

5. 验证安装

pnpm dsh --profile web --dump-config | grep changeproof
# 输出包含 "# == dsh-changeproof" 即安装成功

6. 使用

# 图形界面
pnpm dsh web    # 访问 http://localhost:3080,设置中填入 API Key

# 命令行(需 DEEPSEEK_API_KEY 环境变量)
export DEEPSEEK_API_KEY=sk-xxxxxxxx
pnpm dsh --profile headless "修改 src/calc.ts 的折扣为 75 折并验证"

模型修改代码后会自动调用 changeproof_verify 验证(插件自带工作流规则,无需手动触发)。

卸载

pnpm dsh plugin --profile web remove dsh-changeproof

分发

  • 对方获得插件目录后按步骤 4 add 本地路径;
  • 发布到 npm 后(暂未发布):pnpm dsh plugin add dsh-changeproof。

独立使用(不装 DSH)

cd <插件目录>
npm install && npm run build

node dist/host/cli.mjs plan   --workspace <项目路径>   # 仅分析
node dist/host/cli.mjs verify --workspace <项目路径> --yes   # 执行测试
node dist/host/cli.mjs status --workspace <项目路径>   # 结论是否过期

verify 不带 --yes 仅打印将执行的命令,确认后加 --yes 才执行。

被验证项目的配置

项目根目录放置 .changeproof.yml:

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-webgate 下一个 Next dsh-chaos →