LJH-snow/dsh-tool-gitlab

Plugin插件 ⭐ 2 MIT Dev Workflow开发与代码工作流

Project Overview项目介绍

This repository is a native Cordis tool plugin built exclusively for DeepSeek Harness (DSH), adding enterprise-grade GitLab functionality to DSH agents. It enables DSH agents to complete a full range of GitLab operations via natural language, including end-to-end merge request review, CI/CD pipeline observation and triggering, organization permission auditing, and personal todo inbox management. It follows DSH’s official plugin development architecture and contract, and is purpose-built for self-managed GitLab instances and enterprise governance workflows. Installation can be done directly from GitHub without requiring a pre-publish to npm, or you can clone locally, build the plugin, then install it to your DSH instance. When it is published to npm in the future, it will also be installable via the package name @libai168/dsh-tool-gitlab.

After installation, you need to load the plugin in your DSH composition configuration file, cordis.yml. You will need to add configuration for your GitLab personal access token (PAT) and the base URL of your self-managed GitLab API if you are not using the public GitLab.com instance. Read-only operations do not require a PAT, but any write operations such as merge approval, pipeline triggering, or membership changes require a PAT with the minimum necessary scopes. You should never commit your PAT to any public code repository, as this poses a major avoidable security risk for your organization.

This plugin requires @deepseek-ai/cordis version 4.0.1 or higher and @deepseek-ai/dsh-tools version 0.1.0-rc6 or higher as peer dependencies, which are provided by the host DSH runtime. It is released under the open-source MIT license, so you can modify and redistribute it freely per the license terms. It includes built-in type checking and unit tests with Vitest, making it easy for developers to contribute new features or fix bugs. Business logic errors return clear canonical values instead of throwing exceptions, which helps DSH agents handle expected errors gracefully. Only infrastructure errors throw exceptions.

这是专为DeepSeek Harness(DSH)开发的原生Cordis工具插件,为DSH提供企业级GitLab能力。DSH代理可以通过自然语言完成一系列GitLab操作,包括端到端的合并请求评审、CI/CD流水线观测与触发、群组项目成员权限审计、个人待办事项管理等。它遵循DSH官方插件开发规范,专门针对私有部署GitLab和企业治理工作流设计。

安装方式非常灵活,可以直接通过GitHub仓库地址安装,不需要提前发布到npm,也支持克隆到本地后构建安装。未来正式发布到npm后,还可以通过包名@libai168/dsh-tool-gitlab直接安装。安装完成后需要在DSH的组合配置文件cordis.yml中加载插件,并配置GitLab个人访问令牌和私有部署GitLab的API地址。

本插件需要依赖DSH运行时提供的@deepseek-ai/cordis和@deepseek-ai/dsh-tools作为对等依赖,遵循MIT开源许可。使用时需要注意,只读操作不需要令牌,但写操作、审批、触发流水线等功能都需要配置最小权限的令牌,不要将令牌提交到代码仓库中。插件支持完整的类型检查和单元测试,方便二次开发贡献。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 2 warnings2 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
  • No DSH plugin manifest detected - it may only carry the dsh-plugin topic, so the install method must be confirmed on the spot未检测到 DSH 插件清单:可能只是打了 dsh-plugin 话题,安装方式要现场确认
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:LJH-snow/dsh-tool-gitlab

把 LJH-snow/dsh-tool-gitlab 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-tool-gitlab

English | 中文

A Cordis tool plugin that gives DeepSeek Harness (dsh) enterprise-grade GitLab capabilities. Agents can review merge requests end-to-end (changes, discussions, approvals), observe and trigger CI/CD pipelines, audit group/project membership, and work their personal todo inbox — in natural language.

Built on the official "everything is a plugin" architecture via ctx.tools.register(defineTool(...)), following the official adding-a-tool contract. Designed for self-managed GitLab (baseUrl override) and enterprise governance workflows.

Install

Install directly from GitHub (no npm publish needed):

npm install github:LJH-snow/dsh-tool-gitlab
# or a specific branch/tag
npm install github:LJH-snow/dsh-tool-gitlab#main

Or from a local checkout:

git clone https://github.com/LJH-snow/dsh-tool-gitlab
cd dsh-tool-gitlab
npm install && npm run build   # builds to lib/
npm install /path/to/dsh-tool-gitlab

Once published to npm, it will also be installable as npm install @libai168/dsh-tool-gitlab.

Requires @deepseek-ai/cordis (^4.0.1) and @deepseek-ai/dsh-tools (^0.1.0-rc.6) as peer dependencies, provided by the host dsh runtime.

Configuration

Load the plugin in a dsh composition config (cordis.yml):

- name: 'dsh-tool-gitlab'
  config:
    token: 'glpat_xxx'      # GitLab PAT (optional; required for write tools, approvals, CI triggers, and personal tools)
    baseUrl: 'https://gitlab.com/api/v4'   # optional; point at your self-managed GitLab, e.g. https://gitlab.example.com/api/v4
    timeoutMs: 15000        # optional, request timeout in ms (default 15000)

Full example: examples/cordis.yml.

Security: read-only tools work without a token. Write tools, MR approval/rule management, pipeline triggering/schedules, protected branches, code search on private projects, current-user, and todos require a token. Prefer a minimal-scope PAT (e.g. api + read_repository scopes as needed) and never commit it.

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-llm-kiro 下一个 Next dsh-workbench →