dsh-safe-updater
Manifest validGuarded automatic updates for DeepSeek Harness with isolated profile smoke tests and rollback.
dsh-safe-updater
Guarded updates for DeepSeek Harness. It checks npm releases, clones the selected profile into an isolated DSH_HOME, installs its dependencies, validates the composed config, starts a temporary Web server, and only then allows a supervised switch. Failed candidate health checks roll back to the previous version.
The default mode is notify. Installing this package does not silently replace a running Harness.
Install
dsh plugin --profile web add dsh-safe-updater
The bundle inserts the plugin with this safe default:
- insert:
- id: safe-updater
name: dsh-safe-updater
config:
mode: notify
channel: latest
profile: web
checkIntervalMs: 21600000
checkOnStart: true
Available plugin tools:
dsh_update_status: read current, available, staged, and rollback state.dsh_update_check: check now; behavior follows the configured mode.
Modes
| Mode | Behavior |
|---|---|
notify | Check and record a newer release. Never install or restart. |
stage | Clone the profile and run install, config, and HTTP smoke checks. Never restart. |
apply | Stage, then request a switch from the external supervisor. Refused outside supervisor mode. |
Supervisor and rollback
Run the Web profile under the updater when you want automatic activation:
dsh-safe-updater supervise \
--version 0.1.1-rc.1 \
--profile web \
--host 127.0.0.1 \
--port 3080
Then change the plugin's mode override to apply. When a staged candidate is ready, the plugin writes a version request. The supervisor starts that exact version with argv-based process spawning, waits for HTTP health, commits it, or returns to previousVersion.
Manual commands:
dsh-safe-updater check --current-version 0.1.1-rc.1
dsh-safe-updater stage --version 0.1.1-rc.1 --profile web
dsh-safe-updater status
dsh-safe-updater rollback
Trust and security model
- Registry version strings are parsed as semantic versions and never executed as shell text.
- Candidate commands use argument arrays with
shell: false. .credentials.yaml, sessions, workspaces, and other runtime data are never copied into staging.- State and locks are stored under
~/.dsh/safe-updaterwith restricted permissions and atomic replacement. - Smoke mode disables the updater timer to prevent recursive staging.
- Update errors are logged and recorded; they do not interrupt the agent loop.
The selected profile's npm dependencies are still executable supply-chain inputs. Review and pin third-party plugins. Staging deliberately runs normal install scripts so native plugins are tested faithfully.
Publishing
GitHub Releases are the source and audit trail. npm is the installation channel. After configuring npm trusted publishing for this repository, set the GitHub Actions variable NPM_PUBLISH_ENABLED=true; tagged releases then publish with provenance via .github/workflows/publish.yml. Or publish locally after npm adduser:
npm publish --access public --provenance
License
MIT
Comments
Loading…
Similar plugins
by frostming
Startup auto-updater for DeepSeek Harness (dsh): checks the npm registry once on boot and optionally installs newer versions.
★ 3
MIT
JavaScript
Aug 16, 2026
dsh plugin --profile web add dsh-auto-updateby GodCC6
Auto-update plugin for DeepSeek Harness (git / npm dual-mode) — ff-only pulls, automatic rollback, optional idle-aware auto-apply
★ 0
↓ 78/wk
MIT
JavaScript
Sep 14, 2026
dsh plugin --profile web add dsh-updaterUpdate copilot for DeepSeek Harness: one scan covers the DeepSeek Harness core and every profile plugin; explains what changed and how risky each update is, then updates only what you confirm.
★ 1
↓ 90/wk
MIT
JavaScript
dsh plugin --profile web add dsh-update-copilotby Zhucy123
One-click update for the local DeepSeek Harness checkout — compare versions, pull and rebuild, then restart, and roll back to any past release, all from a sidebar panel with live progress.
★ 0
↓ 212/wk
MIT
JavaScript
Sep 15, 2026
dsh plugin --profile web add @zhucy123/dsh-updateby Muggle8888
Read-only update auditing for DeepSeek Harness profile plugins
★ 0
MIT
JavaScript
Sep 10, 2026
dsh plugin --profile web add dsh-plugin-update-auditby ZK-Andy
Continual self-evolution plugin for DeepSeek Harness: versioned, auditable, rollback-safe harness state refined from session trajectories, with a benchmark-driven validation loop.
★ 20
↓ 2.7k/wk
MIT
TypeScript
Oct 10, 2026
dsh plugin --profile agent add dsh-continual-evolve