kyorakuyk/dsh-hotreload-plugin-manager

DeepSeek Harness插件:在运行的dsh Web中热安装/卸载/更新/启用-禁用配置文件插件包——无需重启,包含Web UI。

Project Overview项目介绍

This is a native out-of-tree plugin built exclusively for DeepSeek Harness (DSH). It allows users to install, uninstall, enable, and disable DSH plugins directly on a running DSH web instance without requiring a full restart of the service. It adds a dedicated plugin management tab to the DSH web settings interface, and supports installing valid DSH plugins from multiple sources including npm packages, git URLs, GitHub shorthand references, and local file paths. Unlike core-integrated plugins, this tool works entirely without modifying any DSH core code, keeping your local DSH checkout completely clean and unmodified.

The plugin reuses existing DSH launcher mechanisms to work, so no core changes are needed. When you install a plugin through this manager, it adds the target plugin as a real dependency to your current DSH profile directory, reads the plugin’s DSH patch configuration, and writes it to the user patch layer. Any changes take effect immediately after installation, and the configuration persists across DSH restarts. For installation requests that do not meet DSH plugin requirements, such as conflicting patch IDs or unresolvable package names, the manager will reject the request and automatically roll back any changes, leaving no residual files.

To use this plugin, you need to meet a few prerequisites first: Node.js version 22 or higher, pnpm version 10 or higher, and a pre-installed DSH with an initialized target profile that you want to add the manager to. You can install it directly via the DSH plugin CLI from GitHub, a local cloned copy, or npm, and you only need to restart your DSH web instance one time after installation completes. It is released under the open-source MIT license, and has a few documented limitations, most notably that changes to plugin module code require a DSH restart to take full effect.

这是一个专为 DeepSeek Harness(DSH)开发的树外原生插件,支持在运行中的 DSH 实例上直接完成插件的热安装、热卸载、禁用启用操作,全程无需重启 DSH 服务。它在 DSH Web 设置页新增了插件管理标签页,支持从 npm 包、git 地址、GitHub 简写、本地路径等多种来源安装符合规范的 DSH 插件,且不需要修改 DSH 内核代码。

它的工作流程复用了 DSH 启动器已有机制,安装时会将插件作为真实依赖添加到当前 profile 目录,读取插件的 DSH 补丁配置写入用户补丁层,操作完成后立即热生效,重启 DSH 后配置也会保留。对于不满足 DSH 插件规范、补丁行 ID 冲突、无法解析包名的安装请求,它会明确拒绝并自动回滚,不会留下残留垃圾文件。

使用本插件需要满足前置条件:Node.js ≥ 22,pnpm ≥ 10,已经安装 DSH 并初始化过目标 profile。安装可以直接通过 DSH 插件 CLI 从 GitHub、本地克隆或者 npm 安装,安装完成后需要重启一次 DSH Web 实例。本插件使用 MIT 许可证开源,已知限制包括模块代码变更需要重启 DSH 才能生效。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add "@kyorakuyk/dsh-plugin-manager"

把 kyorakuyk/dsh-hotreload-plugin-manager 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-hotreload-plugin-manager

中文 | English

一个树外(out-of-tree)DeepSeek Harness 插件:在运行中的实例上直接完成插件的热安装、热卸载、禁用/启用——无需重启, 并提供 Web 设置页标签页:

  • 🔥 热安装:按 spec(npm 包名 / git URL / github:owner/repo / file: 路径) 安装插件 bundle,立即热生效于运行中的 dsh web,且重启后保留。
  • 🔥 热卸载:移除 bundle——行与 fiber 即刻卸载、依赖被清理、陈旧的 bundle 层条目一并移除。
  • 🔥 禁用 / 启用:在 UI 上一键切换已安装 bundle 的条目开关,状态持久化且立即生效。
  • 热更新:热替换 bundle 的补丁行并实时重放配置(模块代码变更按 Node 进程内 缓存特性仍需重启)。
  • 零内核改动:纯树外 bundle,dsh checkout 完全不被触碰。
  • 双面包:一个 npm 包同时是 host 网关与浏览器设置标签页。

架构

┌────────────────────────────── 浏览器(React)──────────────────────────────┐
│  设置 → 插件 → "插件管理"标签页(槽位 settings.plugins.tab)                 │
│        │  fetch('/plugin-manager/*')                                      │
└────────┼──────────────────────────────────────────────────────────────────┘
         ▼
┌──────────────────────────── dsh web 进程 ──────────────────────────────────┐
│  webserver 路由(node:http)──▶ manager 核心                               │
│    ① pnpm add/remove(profile 内的真实依赖)                               │
│    ② 行写入 profile 用户补丁层(cordis.patch.yml)                         │
│    ③ 根 Include entry.update → Loader 挂载/卸载 fiber                      │
│  网关:TypertRemoteService(源码模式反射,无代码生成)                       │
└────────────────────────────────────────────────────────────────────────────┘

包是双面的:

  • Node 半(lib/index.js,tsc 编译)——PluginManagerGateway,一个注册为 pluginManager 的 TypertRemoteService。api-gateway 可通过源码模式反射 分发它的 @Remote 方法(无需生成产物);同时它在 webServer 服务上注册浏览器 HTTP 传输。
  • 浏览器半(lib/client.js,esbuild 打包)——注册进 settings.plugins.tab 槽位(id manager)的 Web 设置标签页,由 dsh-client-modules 发现,并以普通 模块表 bundle(window.__ModuleLoader__.load)形式服务。

工作原理

全部复用 launcher 已有的机制,因此插件不需要对 dsh checkout 做任何改动:

  1. 安装:在 profile 目录执行 pnpm add <spec>。包成为真实依赖(进入 profile 的 node_modules 与 package.json,pnpm 不会剪除它)。管理器读取 该 bundle 的 dsh.bundle.patch 行,写入 profile 的用户补丁层 (cordis.patch.yml)。
  2. 热应用:直接对根 Include 条目调用 entry.update(携带新补丁列表)—— 与 launcher 用户补丁 watcher 相同的调用。管理器自己应用自己的写入,因为文件 watcher 可能漏掉紧跟其后的写入事件。
  3. 重启持久:用户补丁层在启动时被重新组合,因此已安装 bundle 在重启后保留, 且不触碰 dsh.profile.bundles(也就不会双组合行)。
  4. 卸载 / 更新:移除或替换行,并执行 pnpm remove / pnpm update (registry 包)或 remove + re-add(file:/link:——pnpm 的增量重拷不会 物化新增文件)。
  5. 启停:写入用户层禁用行({ id, disabled }),按 id 覆盖 bundle 行而不 产生重复。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-longtask-orchestrator 下一个 Next dsh-powerdesk →