KYinCode/dsh-hot-installer
DeepSeek Harness (dsh) 插件热管理器:装一次、重启一次,之后装插件、卸插件、升级插件全部即时生效,不用再重启。一个能让安装、移除和升级 DeepSeek Harness(dsh)插件即时生效的插件——只需重启一次,之后便无需再重启。
Project Overview项目介绍
dsh-hot-installer is a native Cordis plugin built exclusively for DeepSeek Harness (DSH) to enable hot plugin management without restarts. To install it, you only need to run one simple command: dsh plugin --profile <your-profile-name> add dsh-hot-installer, then restart DSH one single time to activate it permanently. After the initial restart, the plugin runs continuously in the background, monitoring changes to your DSH profile’s plugin manifest file for any additions, removals, or version updates of installed plugins.
When a change to the plugin manifest is detected, the plugin processes it immediately within tens of milliseconds. New plugins are injected directly into the running DSH plugin tree using the same loading channel DSH uses at boot time, so hot installation matches the result of a cold boot exactly. Removed plugins are unloaded from memory instantly, updated plugin versions are unloaded and reloaded automatically, so your daily workflow does not change at all after installation.
The plugin requires Node.js 20 or newer, and only works on long-running DSH instances with HMR support, such as the dsh web interface. It is released under the permissive MIT open-source license, with no costs or restrictions on use. It has one known limitation: on Windows, if you switch the target of a locally linked development plugin during a single DSH run, hot reload will not load the new code, and a restart is required to apply the change. Unit tests for core functions are included in the repository.
这是一款专为 DeepSeek Harness (DSH) 开发的原生 Cordis 插件,核心作用是让 DSH 的插件安装、卸载、更新操作无需重启 DSH 即可即时生效。DSH 默认只会在启动时读取配置文件里的插件清单,运行时修改清单后必须重启才能让改动生效,这个插件将原本必须重启的"冷流程"改成了即时热生效。安装完成后只需要重启一次 DSH,之后它就会常驻运行,持续监听插件清单的任何改动。
开发者或普通用户在使用 DSH 管理插件时,日常操作流程和原来完全一致,只需要正常使用 dsh plugin add/remove/update 命令即可,所有改动都会被这个插件即时处理。新增插件会被直接注入到运行中的插件树,移除插件会直接从内存中摘掉对应条目,版本更新会先卸载旧版本再挂载新版本,整个过程十几毫秒就能完成。这个插件适合所有日常使用 DSH 的用户,能省去每次改插件都要重启等待的麻烦。
这个插件要求 Node 版本不低于 20,仅能在支持 HMR 的长驻 DSH 服务(如 dsh web)上生效,一次性命令行场景无法激活监听。它遵循 MIT 许可开源,无任何使用成本,已知限制是 Windows 上使用 link 方式本地开发插件时,同一次运行中切换 link 目标后热更新不会加载新代码,需要重启 DSH。所有操作日志都会保存在 ~/.dsh/logs/dsh-hot-installer/ 目录下,方便排查问题。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-hot-installer(KYinCode/dsh-hot-installer)
仓库:https://github.com/KYinCode/dsh-hot-installer
本站详情页:https://www.yhbd.top/plugins/kyincode-dsh-hot-installer/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 9 · 最近提交 2026-09-22 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 9 stars - very few users, little community feedback星标只有 9,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-hot-installer
把 KYinCode/dsh-hot-installer 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-hot-installer
给 DeepSeek Harness 装上之后,dsh plugin add / remove / update 都不再需要重启。 装一次、重启一次,之后这个插件替你监听 profile 的插件清单:新装的包当场挂载、卸掉的包当场卸载、升级的包当场重载;就算你手动编辑了补丁文件,它也会把被冲掉的热装行自动补回来。
我需要装吗(按 dsh 版本看)
| 你的 dsh | 平台自身能力 | 这个插件提供什么 |
|---|---|---|
0.1.5-rc.2(npm latest,普通用户默认装到的) |
HMR 只监听补丁文件,完全不看 profile 清单:装/卸/升级都必须重启才生效 | 全部能力——装、卸、升级三种操作都免重启 |
0.1.6-alpha.2 及以后 |
平台自带 dsh-hmr 接管清单,装/卸已原生免重启 |
补平台跳过的部分:依赖版本升级(add pkg@新版本)仍免重启;另带预检、失败回滚、紧急卸载保护链 |
结论:稳定版用户装它不是没用,而是全靠它;alpha 新版用户装它仍有价值(平台不管版本升级,也不做失败回滚)。哪天平台把这两件也做了,这个插件就可以卸载了。
该矩阵已于 2026-09-22 用隔离环境实测复核:把
@deepseek-ai/dsh@0.1.5-rc.2装到临时目录、DSH_HOME/USERPROFILE双隔离后,用旧版自己的 CLI 装dsh-hot-installer@0.5.4并启动——日志为hot install/remove/reload enabled, v0.5.4(完整能力模式),热装hot-applied+ 目标 bundle 当场激活、热卸hot-removed全部成功。
这是什么
DeepSeek Harness 里一切皆插件,但你用 dsh plugin --profile web add <pkg> 装一个新 bundle 后,必须重启 dsh web 它才生效——因为 profile 的插件清单(package.json 里的 dsh.profile.bundles)只在启动时读取,运行中的进程不会再看它。卸载更糟:dsh plugin remove <pkg> 把包从磁盘删掉,但已挂载的插件行还留在内存里,此时刷新网页会看到 "Failed to load plugins" 报错(客户端还在向已删除的包要代码)。版本更新同样冷:新代码要等重启才会被加载。
这个插件把这条唯一的"冷路径"变热。它装好后常驻在 profile 里,监听清单文件的变化:发现新 bundle 就读取该包声明的补丁(cordis.patch.yml),把里面的插件行注入到运行中的插件树,loader 的 diff 机制当场激活(实测十几毫秒);发现 bundle 被移除,就按"包→行"映射把对应行从树里摘掉;发现版本号变了,就把行摘掉再重挂,让 loader 重新加载新模块。整个过程不写任何配置文件、不改你的补丁层,重启后依然与正常启动完全一致。
安装与使用
# 一次性安装(换成你实际在用的 profile 名),然后重启一次 dsh
dsh plugin --profile web add dsh-hot-installer
重启之后,插件就永久生效了,日常操作和原来一模一样:
dsh plugin --profile web add some-plugin # 立即生效,不用重启
dsh plugin --profile web remove some-plugin # 立即卸载,不用重启,页面也不会报错
dsh plugin --profile web add some-plugin@latest # 立即升级重载,不用重启
日志在 ~/.dsh/logs/dsh-hot-installer/dsh-hot-installer.log,每次热装/热卸/热重载都有记录(如 hot-applied dsh-alive (1 patch entry)、hot-removed dsh-alive (1 patch entry)、hot-reloaded dsh-pomodoro (0.1.0 -> 0.3.0, 1 patch entry))。
工作原理
清单文件每次变化(dsh plugin add 会写两次:pnpm 写依赖、再同步 bundles 列表,插件用 300ms 防抖合并),插件对比自己维护的快照(包名 → 版本号)找出新增、移除和升级的包。对新增的包:从 profile 的 node_modules 解析出包目录,读取它 package.json 里 dsh.bundle.patch 指向的补丁文件(用与启动完全相同的 YAML 方言解析,包括 !!js 表达式),把解析出的 patch 条目追加到根 include entry 的 config.patches 并调用 entry.update——这正是启动时挂载插件的同一条通道,所以热装与冷装的结果完全一致。对移除的包:把该包贡献的 patch 条目从 config.patches 里按深度相等逐个摘除再 entry.update,loader 卸载对应行。对升级的包:先摘除旧行再重新挂载新行,loader 会重新 import 拿到新版代码(绕开 ESM 模块缓存)。包→行的映射在启动时对清单里所有包建立(重启后 boot 挂载的包同样可热卸),每次热装时更新,只存在于内存。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
yannicksong0106/dsh-550c-boot
vecnode/vncode