frostming/dsh-auto-update

Collection合集 Native原生 ⭐ 3 MIT Markets & Collections市场与合集

DeepSeek Harness(dsh)启动自动更新器:在启动时检查npm注册表一次,并可选择安装更新版本。

Project Overview项目介绍

This is a host-side startup auto-update plugin for DeepSeek Harness. It checks for new versions on the npm registry when DSH starts, defaults to notify only of updates, and can be configured to auto-install updates. Use it when you want automatic DSH update checks. Note enabling auto-install means accepting the risk of official breaking changes.

这是DeepSeek Harness的宿主端启动自动更新插件,弥补官方CLI无自更新能力的不足。启动时对比本地版本与npm registry版本,默认仅提醒更新,可配置为自动安装更新。需要自动检查DeepSeek Harness更新时使用。注意开启自动安装需接受官方可能的破坏性变更风险。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:frostming/dsh-auto-update

把 frostming/dsh-auto-update 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-auto-update

一个运行在宿主端的 DeepSeek Harness 启动自动更新插件。

DeepSeek Harness 官方 CLI 没有 self-update,社区里已有的插件(如 dsh-update-checker)只能检查更新、然后让用户点按钮手动安装。这个插件补上"无人值守"这一环:每次启动时对比本机 dsh --version 与 npm registry 的 dist-tag,发现新版本时按配置只提醒(默认,安全)或自动安装(需显式开启)。

特性

  • 启动时检查一次:启动后延迟几秒自动检查一次,之后不再重复检查
  • 正确的 semver 比较:正确处理 0.1.0-rc.5 → 0.1.0-rc.6 这类预发布版本
  • 两种模式:
    • notify(默认):只在控制台打印醒目的"发现新版本"横幅,不安装
    • install:自动执行安装命令(默认 npm install -g @deepseek-ai/dsh@<version>)
  • 状态持久化:检查结果写入 ~/.dsh/dsh-auto-update-state.json,保留最近 10 次历史
  • profile 无关:不依赖 webServer,web / headless / tui / 任意自定义 profile 都能用
  • 优雅卸载:启动检查的 setTimeout 通过 ctx.effect 注册,HMR 替换或插件卸载时自动清理
  • 零运行时依赖:只用 Node 内置模块 + 全局 fetch

安装

dsh plugin --profile web add github:frostming/dsh-auto-update
# 或从本地 checkout 安装
dsh plugin --profile web add /path/to/dsh-auto-update

重启 dsh web 生效。默认只提醒不安装,控制台会打印:

════════════════════════════════════════════════════════
  dsh-auto-update: update available
    installed: 0.1.0-rc.5
    available: 0.1.0-rc.6 (latest)
    action:    notify only — run npm install -g @deepseek-ai/dsh@0.1.0-rc.6
════════════════════════════════════════════════════════

开启自动安装

编辑 profile 的 cordis.patch.yml($DSH_HOME/profiles/<name>/cordis.patch.yml),覆盖 mode:

- insert:
    - id: dsh-auto-update
      name: 'dsh-auto-update'
      config:
        mode: install
        # 可选:自定义安装命令,{version} / {package} 会被替换
        installCommand: 'npm install -g {package}@{version}'

⚠️ DeepSeek Harness 目前处于 developer preview,官方明确声明会有破坏性兼容变更。自动安装等于接受这种风险,请谨慎开启。

配置项

键 默认值 说明
channels ["latest", "next"] 按优先级咨询的 dist-tag
startupDelayMs 5000 启动后检查的延迟,毫秒
mode "notify" "notify" 或 "install"
installCommand npm install -g {package}@{version} 安装命令模板
stateFile ~/.dsh/dsh-auto-update-state.json 状态文件路径
verbose true 是否打印检查日志

目录结构

dsh-auto-update/
├── package.json        # dsh bundle 声明(dsh.bundle.patch)
├── cordis.patch.yml    # 插入插件行到 profile 层级栈
├── lib/
│   ├── index.js        # 宿主端:启动时一次性检查 + 决策 + 安装执行
│   ├── semver.js       # 无依赖的 semver 比较
│   ├── version.js      # 本地版本解析 + npm registry 查询
│   └── state.js        # 状态持久化
└── test/               # node --test 单元测试

测试

npm test

License

MIT

← 上一个 Prev dsh-plugin-photoshop 下一个 Next dsh-whale-pet →