dsh-pack
Portable, reproducible and verifiable runtime artifacts for DeepSeek Harness
why-daydream
@why-daydream
⬇ 1
★ 0
main
安装
dsh plugin --profile web add github:why-daydream/dsh-pack
需要可复现安装时,可在仓库后追加 #commit 固定提交。
Portable, reproducible and verifiable runtime artifacts for DeepSeek Harness
该插件未提供要点说明,请参考仓库 README。
- 安装并启动 DeepSeek Harness:
npx @deepseek-ai/dsh web - 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
- 用 dsh plugins list 确认已安装,必要时重启 Harness 生效
插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。
| 代码仓库 | github.com/why-daydream/dsh-pack |
| 许可证 | MIT |
| 主要语言 | main |
| 下载量 | 1 |
| GitHub 星标 | 0 |
| 最近推送 | 2026-09-05 |
| 收录日期 | 2026-09-19 |
| 分类 | 开发与运行时 |
事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。
以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。
# dsh-pack
> **Reproducible, portable, signed, runnable and OCI-distributable Agent Artifacts for DeepSeek Harness.**
>
> `npm install @why-daydream/dsh-pack`
**English** · [简体中文](./README.zh-CN.md)
[](https://www.npmjs.com/package/@why-daydream/dsh-pack)
[](https://github.com/WHY-Daydream/dsh-pack/releases/tag/v0.6.0)
[](https://github.com/WHY-Daydream/dsh-pack/actions/runs/33292227705)
[](LICENSE)
---
## Install
### DSH Plugin (recommended)
```bash
dsh plugin --profile demo add @why-daydream/dsh-pack
```
Pin a version:
```bash
dsh plugin --profile demo add @why-daydream/dsh-pack@0.6.0
```
### npm
```bash
npm install @why-daydream/dsh-pack
```
---
## 30s Quick Start
```bash
# Install the plugin
dsh plugin --profile demo add @why-daydream/dsh-pack
# Pack a profile into a reproducible .dshpack
/pack web --portable
# Inspect the artifact
/pack inspect web-.dshpack
# Verify integrity + signature
/pack verify web-.dshpack --require-signature
```
### End-to-End Pipeline
```text
Profile
↓ /pack
.dshpack
↓ /sign
Trusted Artifact
↓ image import
Agent Image
↓ /push
GHCR / OCI Registry
↓ image lock + trust.yaml
Governed Runtime
```
## Demo
Reproducible terminal recording of the full chain (pack → sign → import → lock → verify → run):
```text
contentHash: sha256:...
Signature: VALID
Trust: VERIFIED
demo/agent:prod
→ ghcr.io/.../agent@sha256:
Agent image started
```
- Recording script: `demo/recording/demo.sh` (`DEMO_MODE=local` by default; `DEMO_MODE=ghcr` shows real push/lock)
- Deterministic recording: `demo/recording/demo.tape` (VHS)
---
## Version Evolution
```text
v0.1 Snapshot — Reproducible profile configuration snapshot
↓
v0.2 Portable — Ships local dependencies together
↓
v0.3 Trusted — Ed25519 signing + provenance verification
↓
v0.4 Runnable — Agent Image model: named, versioned, runnable
↓
v0.4.1 Distributed — OCI push/pull (GHCR, Docker Hub, any registry)
↓
v0.4.2 Governed — image lock + trust.yaml + local prune + Real GHCR 8/8 PASS
↓
v0.5.0 Verifiable — Evidence Chain (provenance / SBOM / capability / attestation) + Trust Policy v2
↓
v0.6.0 Distributed — OCI Referrers Evidence 分发(discovery / publication / cache / trust / interop)+ 真实 GHCR gate PASS
```
---
## Architecture — Artifact Supply Chain
[图片: dsh-pack Artifact Supply Chain Architecture]
> Editable Mermaid source: [`docs/architecture.md`](docs/architecture.md) (README renders the SVG by default for consistent cross-platform display).
### Identity Model — Four Layers
```text
configHash
↓
Profile reproducibility
contentHash
↓
DSH artifact identity / signing
OCI blobDigest
↓
Transport bytes integrity
OCI manifestDigest
↓
Remote immutable image identity
```
### Core Invariants
```text
Lock ≠ Trust — Version governance ≠ execution governance
Cache ≠ Trust — A cached image is not automatically trusted
Registry ≠ Trust Authority — The registry is a distribution channel, not a trust source
VALID ≠ TRUSTED — A valid signature from an unknown key is still untrusted
OCI Digest ≠ DSH contentHash — Transport identity ≠ artifact identity
CLI can tighten policy, never weaken it
```
---
## Commands
| Command | Description |
|------|------|
| `/pack [name]` | Pack the current profile (`--strict` / `--out` / `--allow-secrets` / `--allow-nonportable`) |
| `/pack --portable` | Pack with local `file:`/`link:` dependencies vendored |
| `/pack inspect ` | Show an artifact summary (`--json`) |
| `/pack verify ` | Verify integrity: Manifest / Config / Packages / Checksums / DSH Version / Signature (`--json`, `--require-signature`) |
| `/pack install ` | Restore to `$DSH_HOME/profiles/` (staging + atomic swap + frozen-lockfile) |
| `/pack diff ` | Compare configuration drift between two packs: Manifest / Bundles / Config / Dependencies + configHash |
| `/pack keygen [--out ]` | Generate an ed25519 keypair (v0.3: private key chmod 600 + public key + keyId) |
| `/pack sign --key [--signer ]` | Embed a signature + provenance, produce `.signed.dshpack` (v0.3) |
| `/pack image import` | Import a `.dshpack` as a local Agent Image (tag / digest) |
| `/pack image ls` | List local Agent Image repositories |
| `/pack image tag` | Add / move a tag on a local image |
| `/pack image rm` | Remove a local image / tag |
| `/pack image lock` | Freeze a mutable remote tag to an immutable manifest digest |
| `/pack image prune` | Mark-and-sweep GC: remove unreachable manifest/blob (dry-run default, `--apply` deletes) |
| `/pack push ` | Push an Agent Image to an OCI Registry (GHCR / Docker Hub) |
| `/pack pull ` | Pull an Agent Image and verify integrity |
| `/pack run [--require-trusted]` | Run an Agent Image (integrity + trust policy + temporary runtime or persistent profile) |
---
## Distribution
### npm
```bash
npm install @why-daydream/dsh-pack
```
📦 [@why-daydream/dsh-pack](https://www.npmjs.com/package/@why-daydream/dsh-pack) — `v0.6.0`
### GitHub Release
🔖 [v0.6.0 — Distributed Verifiable Evidence](https://github.com/WHY-Daydream/dsh-pack/releases/tag/v0.6.0)
### OCI / GHCR
Protocol-tested against GHCR: **8/8 items PASS** ([run #33292227705](https://github.com/WHY-Daydream/dsh-pack/actions/runs/33292227705)).
```text
① Bearer challenge ② Token acquisition (pull,push)
③ HEAD blob 404 → 200 ④ POST uploads/ → PUT ?digest → 201
⑤ OCI manifest PUT ⑥ Tag pull Content-Type + Docker-Content-Digest
⑦ Digest pull identity ⑧ DSH contentHash + Signature + Trust + run configHash
```
### DSH Community
📢 [DSH Discussion](https://github.com/WHY-Daydream/dsh-pack/discussions) — community discussion and usage
---
## Verification Status
| Dimension | Status |
|------|------|
| Local test suite | **140 tests / 21 files** — all passing (mock OCI registry, signing E2E, trust policy, image lock, GC prune) |
| typecheck (`tsc -b`) | ✅ Passing |
| lint (`oxlint`) | ✅ 0 errors |
| Real GHCR E2E | ✅ **8/8 PASS** (run 33292227705, 2026-08-30) |
| npm tgz clean-room | ✅ install + import passing |
| npm registry | ✅ published + install + import passing |
---
## Known Limitations
1. **pnpm v11 virtual-store layout**: after `--portable` restore, transitive `file:` dependencies may live under `.pnpm` virtual storage instead of top-level `node_modules`. Functionality and the frozen-install loop still hold; byte-for-byte `node_modules` layout parity is limited by pnpm behavior, not a package defect.
2. **Three real engineering pitfalls fixed in `--portable`** (all covered by regression tests; see `DESIGN.md` Appendix D and `TRACEABILITY.md`):
- async staging race (early `return` before `await` deleted the staging dir → intermittent ENOENT);
- the rewritten `package.json` being overwritten by the copy step;
- pnpm lockfile's project-relative `file:` semantics (addressed relative to the project root, not the declaring dir).
3. **Non-reproducible items**: floating git branches (no `#commit` anchor, fail under `--strict`); home-layer and `--patch` overlays (machine/invocation-local, not packed but warned); `--allow-nonportable` output is `installable:false` and install refuses it by default.
4. **Security boundary**: `.dshpack` forbids real secrets (composite-tree scan + redaction to `${VAR}` + `.env.example`; install never restores secrets); archive extraction guards against path traversal and symlink/hardlink/device entries.
---
## Docs
- `DESIGN.md` — frozen protocol (format, hash algorithms, security model, command behavior)
- `DESIGN-v0.4.2.md` — four-layer Governance design (image lock / trust.yaml / local prune / GHCR 8/8)
- `DESIGN-v0.5.0.md` — Evidence Chain + Trust Policy v2 (D64–D139)
- `TRACEABILITY.md` — trace each frozen decision → source file → test case
- `CHANGELOG.md` — version history
- `LICENSE` — MIT
---
## License
MIT © [WHY-Daydream](https://github.com/WHY-Daydream/dsh-pack)
数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。