wqx11235/dsh-upgrade-guard
DSH 升级守卫:升级前兼容盘点 / 升级后契约扫描 / 启动冒烟(DeepSeek Harness 插件)
Project Overview项目介绍
dsh-upgrade-guard is a native upgrade-guard bundle for DeepSeek Harness (DSH) that turns every past post-mortem into a reusable rule, codified in lib/guard.mjs as KNOWN_RULES. It exposes three actions through the host route POST /api/dsh-upgrade-guard and through node lib/guard.mjs: an offline "scan" that flags removed services such as settingsScope and conversationEvents, the deprecated session message source: { kind: 'plugin' } V3 form, references to primitives exports no longer present in @deepseek-ai/dsh-client-ui-primitives, and exact-pinned plugin versions that drift behind the host; a network "preflight" (10–40 s) that walks each installed plugin, reads its declared compatibility range from npm, and produces a "can I upgrade + which to upgrade together + disable list" matrix; and a "smoke" pass (30–90 s) that boots the candidate host on port 3099, captures SKIPPED / PENDING / DEGRADED / BADBUNDLE entries, probes every client bundle for reachability, and only returns PASS when the bundle tree is clean — the test process is killed by default unless DSH_SMOKE_KEEP=1.
The bundle targets DSH operators who keep non-trivial profile bundles and have been bitten by cascading failures such as "31 plugins pending" after a 0.1.2→0.1.5 host bump or a React #130 crash after the 0.1.7-alpha.1 primitives rename. Console output is intentionally ASCII to survive Windows cmd code page 936; Chinese reports are written to the --report file. Every new breakage is meant to be added to KNOWN_RULES, so the tool gets sharper with use.
Install with pnpm add github:wqx11235/dsh-upgrade-guard inside %USERPROFILE%\.dsh\profiles\web, append the bundle name to dsh.profile.bundles, restart the host via the desktop shortcut or restart-dsh-web.cmd, then Ctrl+F5 and open Settings → General → 升级守卫. Limits: smoke covers only startup, not render-time React errors; scan only sees rules already in KNOWN_RULES; preflight cannot resolve github:... git/url sources to a latest version; host-skipped bundles are reported as SKIPPED and require dsh plugin allow-version to re-enable. License: MIT.
dsh-upgrade-guard 是面向 DeepSeek Harness(DSH)的原生升级守卫插件,把每次排障得到的破坏性契约沉淀为可复用的检查规则。它在升级前做联网盘点(拉取插件 npm 元数据判断兼容范围)、平时做离线契约扫描、切换端口前在测试端口(默认 3099)跑启动冒烟,三步闭环降低宿主版本升级后"页面 Failed to load plugins"或"31 个插件连锁 pending"这类连环崩溃的概率。
典型用法:进入 DSH "设置 → 通用 → 升级守卫"点击三个按钮,或在命令行执行 node lib/guard.mjs scan|preflight|smoke,支持 --json --report file.md 输出中文报告。它适合长期维护多插件 profile 的 DSH 用户、需要在团队内统一升级节奏的维护者,以及每次 DSH 发版前都想先冒烟再切的谨慎型玩家;冒烟通过后才建议切换主端口,结束时默认必杀进程。
依赖方面仅需 Node.js 与 pnpm,按 pnpm add github:wqx11235/dsh-upgrade-guard 装入 %USERPROFILE%\.dsh\profiles\web 后写入 dsh.profile.bundles,重启宿主并 Ctrl+F5 即可启用。局限:冒烟只覆盖启动期不覆盖渲染期 React #130 类错误;契约扫描仅识别 KNOWN_RULES 中已收录的破坏模式;git/url 源插件查不到最新版需人工核对;license 为 MIT。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-upgrade-guard(wqx11235/dsh-upgrade-guard)
仓库:https://github.com/wqx11235/dsh-upgrade-guard
本站详情页:https://www.yhbd.top/plugins/wqx11235-dsh-upgrade-guard/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-09-28 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:wqx11235/dsh-upgrade-guard
把 wqx11235/dsh-upgrade-guard 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-upgrade-guard · DSH 升级守卫
让「更新 DeepSeek Harness 本体」不再变成「更新一次崩一次」。 升级前盘点插件兼容性 → 升级后扫描已知破坏性契约 → 切换端口前先启动冒烟,不通过就别切。
DeepSeek Harness(dsh) 的插件生态很活跃,但宿主每次升级都可能改契约,跟在后面的插件就容易崩。真实案例(同一个坑反复出现):
| 事故 | 根因 | 症状 |
|---|---|---|
| 0.1.1 → 0.1.2 | client-modules 模块表变严 | 页面 Failed to load plugins |
| 0.1.2 → 0.1.5 | 服务访问契约变严(inject 缺失即崩) |
31 个插件连锁 pending |
| 0.1.6 → 0.1.7 | 服务 settingsScope 被移除/改名 |
26 个插件 pending(Console 只有 4 条真节点) |
| 0.1.7-alpha.1 | primitives 图标改名(IconXxx14 → IconXxxRegular,无别名) |
插件面板 Minified React error #130(元素类型 undefined) |
| 0.1.7 | 会话消息 V4 source 契约 |
某轮对话跑完后失败:format v4 message requires a producer-owned source kind |
这些都是运行库版本升级 → 底层契约变更 → 插件没跟上。本插件把每次排障得到的判据固化成可复用检查。
三个动作
| 动作 | 什么时候用 | 做什么 |
|---|---|---|
| 契约扫描(离线,秒级) | 平时 / 升级后 | 按「已知破坏性契约」目录扫已装插件:被移除的服务名、会话消息旧 source 写法、引用了宿主导出表里不存在的 primitives 成员 |
| 联网盘点(10–40 秒) | 升级前 | 逐个插件看:声明了什么兼容范围、npm 上有没有新版、新版是否声明支持目标版本 → 产出「能不能升 + 哪些要一起升 + 停用清单」 |
| 启动冒烟(30–90 秒) | 切换端口前 | 在测试端口(默认 3099)起一次被检查的宿主 → 抓「被 peer 门跳过的插件 / 功能降级 / pending / 插件树真凶」+ 逐个探 client bundle 可达性 → PASS 才建议切换;结束必杀测试宿主 |
安装
三种方式,任选:
# ① 直接从一个 GitHub 仓库装(pnpm 会拉取并安装到 profile)
cd $env:USERPROFILE\.dsh\profiles\web
pnpm add github:wqx11235/dsh-upgrade-guard
# 然后把它加进 profile 的 dsh.profile.bundles:编辑 package.json 的 dsh.profile.bundles 数组,加入 "dsh-upgrade-guard"
# ② 手动放置(无网络依赖)
# 把本仓库整个目录复制到 %USERPROFILE%\.dsh\profiles\web\node_modules\dsh-upgrade-guard
# 同样把它加入 dsh.profile.bundles
# ③ 通过 dsh 插件市场安装(若已上架)
装完重启宿主(桌面快捷方式 / restart-dsh-web.cmd),浏览器 Ctrl+F5,然后进 设置 → 通用 → 升级守卫。
使用
在界面里
设置 → 通用 → 升级守卫,三个按钮:
- 契约扫描 →
⚠ 契约扫描:critical N / warn N(扫了 M 个插件)+ 明细 - 联网盘点 →
📋 联网盘点(目标 x.y.z):N 个插件,K 个有新版+ 新版本清单 - 启动冒烟 →
✅ 启动冒烟:PASS/❌ FAIL+ 关键输出行(ROOT?/PENDING/SKIPPED/DEGRADED/BADBUNDLE)
命令行(同一份引擎)
node lib/guard.mjs scan --json --report report-scan.md
node lib/guard.mjs preflight --json --report report-preflight.md --target 0.1.8-rc.1
node lib/guard.mjs smoke
smoke 用环境变量配置:
| 变量 | 说明 | 默认 |
|---|---|---|
DSH_SMOKE_BIN |
要冒烟的 dsh 入口(.../dsh/lib/bin.js) |
当前安装 |
DSH_SMOKE_PORT |
测试端口 | 3099 |
DSH_SMOKE_CWD |
启动工作目录 | 当前目录 |
DSH_SMOKE_TIMEOUT |
等待就绪秒数 | 120 |
DSH_SMOKE_KEEP=1 |
跑完不杀测试宿主(排障用) | 关 |
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
HakureiMonika/dsh-sandbox-escalation-fix
PerryLink/dsh-claude-move
MutaLucem/dsh-plugin-integration
arkyu2077/awesome-dsh-plugin
SpookyWaste/dsh-bash-native
whitefirer/dsh-browser-fs