DSH Plugins Marketplace

DSH Plugins

Plugins

/

dsh-plugin-upgrade

P

dsh-plugin-upgrade

Manifest valid

Plugin-author upgrade skill for DeepSeek Harness: one package, one corridor index - it detects the caller peer band, routes to the matching closed corridor card (0.1.3-alpha.1 -> 0.1.5-rc.1, 0.1.5-rc.2 -> 0.1.6-alpha.2) and runs a zero-dependency seam scanner as a bundle skill + npx CLI.

hasBundlePatch

⬆️ dsh-plugin-upgrade

  • 1024 store channel: npm i -g dsh1024 once, then dsh1024 plugin --profile web add dsh-plugin-upgrade (counts toward the deepseek1024.com install ranking). Gitee dshfind OpenSSF Scorecard

Plugin upgrade skill for DeepSeek Harness — one package, one corridor index, two closed corridors: 0.1.3-alpha.1 → 0.1.5-rc.1 (legAB) and 0.1.5-rc.2 → 0.1.6-alpha.2 (legC).

The scanner routes itself: it reads the target repository's declared dsh band (or takes --span), then applies that corridor's own evidence-bound catalog — legAB's 20 seams (leg A 0.1.3-alpha.1 → 0.1.5-alpha.1 plus leg B 0.1.5-alpha.1 → 0.1.5-rc.1) or legC's 5 seams (E1–E5). One entry point, so a client half that stopped mounting silently is never mistaken for "typecheck is green".

Official repository. This is the only official repository of dsh-plugin-upgrade, maintained by PerryLink. It supersedes the retired version-locked packages dsh-plugin-upgrade (leg A) and dsh-plugin-upgrade-rc1 (leg B), and it is the package the 0.1.5-rc.2 → 0.1.6-alpha.2 corridor (leg C) was folded into — the dsh-plugin-upgrade-016 name never reached the registry. Same-name repositories under other accounts are not affiliated.

License DSH plugin dsh-doctor DSH Market Node CI Version npm version npm downloads

English · 简体中文 · Español · Português · हिन्दी


⭐ 如果它帮到了你

这个插件是 DSH 插件家族的一员(40+ 个,全部 Apache-2.0)。如果你在用,给个 star —— 它不会解锁任何功能,但会让下一个人在搜索里更容易找到它。

English: part of a 40+ plugin family for DeepSeek Harness. If it is useful, a star helps the next person find it — nothing is gated behind it.

Compatibility

SurfaceStatus
HarnessDeepSeek Harness 0.1.5-rc.1 (tag dsh-v0.1.7-alpha.2 = 183f08e9c6dd; leg A→B handoff dsh-v0.1.7-alpha.2 = 5dda764ed3aa; corridor start 0.1.3-alpha.1) and, for legC, DeepSeek Harness 0.1.6-alpha.2 (tag dsh-v0.1.7-alpha.2). Peer band @deepseek-ai/dsh-skill >=0.1.2-rc.1 <0.2.0 || >=0.1.5-alpha.1 <0.2.0 || >=0.1.6-0 <0.2.0 || >=0.1.7-0 <0.2.0, @deepseek-ai/cordis ^4.0.2, @deepseek-ai/schemastery ^3.18.2.
Node^22.19.0 || >=24.0.0
PlatformsAnywhere Node runs; the scanner is filesystem-only and platform-neutral
ModelText-only models fully supported; the skill is a Markdown body, no tool or vision requirement
Corridor indexOne package, one entry point. lib/route.mjs holds the closed corridors and the CLI routes to the matching one from the target repo's declared band (engines.dsh, the @deepseek-ai/dsh* ranges); --span legAB|legC overrides the guess and an undeclared band falls back to the older corridor. The two catalogs are never merged: each corridor keeps its own seam array, card, evidence, fixtures and parity gate.
ScopeTwo closed corridors: legAB = 0.1.3-alpha.1 → 0.1.5-rc.1 (leg A + leg B), legC = 0.1.5-rc.2 → 0.1.6-alpha.2. A corridor never widens: a hop that adds a seam is a new corridor — a new card and a new index row, not a new package.
LegsEvery leg lives in this package: leg A keeps the S1–S10 + M1 seams, leg B keeps C1, C2, C4, C5, H1–H4, P1, and leg C keeps E1–E5 — each with its own evidence, card section, fixtures and rollback path. There is no sibling package to install.
C3Retired: leg B's card spelled the stale-type-line false green C3, which is the same defect as leg A's M1. The fold is recorded on the card; --seams C3 matches nothing.
SiblingDo not mount the retired dsh-plugin-upgrade in the same profile: both register the agent skill plugin-upgrade, so the second mount collides on the skill name. That package is deprecated on npm and its repository is retired; this package replaces both of its legs.

What you get

Two halves, one seam catalog per corridor:

  • A bundled agent skill (plugin-upgrade) — the corridor cards and a fix-and-verify loop. The body first routes the caller to the corridor that matches its peer band; the model loads it only when a task actually needs it, and the package contributes no system-prompt paragraph and no tool.
  • A zero-dependency CLI (dsh-plugin-upgrade-scan) — resolves the corridor and reports file:line facts for that corridor's seams: legAB's twenty (S3, S8, S9, M1, S4, S5, S6, S7, S2, S1, S10, C1, C2, P1, C4, C5, H1, H2, H4, H3) re-read from the harness tag ranges on 2026-09-09 (leg A) and 2026-09-10 (leg B), or legC's five (E1–E5) measured on dsh-v0.1.7-alpha.1 (2026-09-19). Exit 1 on any error-severity hit, so it drops straight into CI.

The point is the failure mode this corridor exists to kill: this span's breakage is mostly silent, from both ends. The type line can be stale, so the repo compiles against the old catalog (seam M1), and the bare conversation client slot was deleted with no alias while ctx.slots.inject() only runs its callback when the declaration exists — so a client half that still targets it stops mounting with no error, no log line and no failed build (seam C1). Three classes of breakage survive typecheck + test:

  1. the local gate compiles a stale type line — old paths alias, or dev/test types pinned at 0.1.5-alpha.* (seam M1);
  2. a log writer omits the V3 required stream field, so the session imports and then refuses to resume (seam S3);
  3. the tests are mocked against the old shape, so they pass while the host drops the contribution (seam C1).

Honest sizing: leg B's workspace sweep found that the family's client halves use only 8 slot keys, all of which survive in rc.1 — for them the rc.1 breakage is latent, not actual. Third-party client plugins that targeted the bare conversation key are the ones that break, and they break quietly. Leg A's sweep found the opposite texture: 40 repos, 11 of them hit M1, and fixing the stale path exposed real TypeScript errors in 3 repos that were previously "green".

Quick start

# 1. install the bundle into your profile
dsh plugin --profile web add dsh-plugin-upgrade

# 2. verify the row mounted
dsh --profile web --dump-config | grep -A3 'id: dsh-plugin-upgrade'

# 3. scan the plugin you are upgrading
npx dsh-plugin-upgrade-scan --repo ../my-plugin

Then ask the agent to use the plugin-upgrade skill, or drive the loop yourself with the card that matches your band: skills/plugin-upgrade/references/v0.1.3-alpha.1-to-v0.1.5-rc.1.md (legAB — leg A is §1, leg B is §2, the merged seam index is §3) or skills/plugin-upgrade/references/v0.1.5-rc.2-to-v0.1.6-alpha.2.md (legC). The scanner picks the corridor for you; add --span legC when the declared band is ambiguous.

Install & uninstall

dsh plugin --profile web add dsh-plugin-upgrade            # from npm
dsh plugin --profile web add "github:PerryLink/dsh-plugin-upgrade#main"   # from source
dsh plugin --profile web remove dsh-plugin-upgrade         # uninstall (reversible)

Installing the bundle only registers a skill; removing the row removes the skill. The CLI is a normal npx target and needs no profile at all.

Configuration

Every key is optional and lives in the profile patch:

KeyDefaultMeaning
enabledtrueRegister the packaged skill. Set false to keep the dependency mounted but silent.
skillNameplugin-upgradeDirectory under skillsRoot to register, and the name shown in the catalog.
skillsRootthe package's own ./skillsWhere <skillName>/SKILL.md lives. Point it at your own card to reuse the plumbing.
userInvocabletrueWhether a human can invoke the skill by name in addition to the model.
- insert:
    - id: dsh-plugin-upgrade
      name: dsh-plugin-upgrade
      config:
        skillName: plugin-upgrade

The plugin mounts loud: a missing SKILL.md, an empty body, or a frontmatter without name fails the mount instead of registering an empty skill.

Surfaces

Skill — plugin-upgrade (model- and user-invocable by default). Body: leg routing table, the 8 hard rules and the 6-step loop. References: the merged corridor card. Scripts: the detector, shipped inside the skill directory so relative paths resolve.

CLI — dsh-plugin-upgrade-scan:

dsh-plugin-upgrade-scan [--repo <path>] [--span legAB|legC|<span>] [--json <out.json>] [--seams S3,C1,P1] [--quiet]
FlagMeaning
--repo <path>Repository to scan (default: cwd). Its declared dsh band chooses the corridor.
--span legAB|legC|<span>Force a corridor instead of guessing from the declared band. An unknown band falls back to legAB.
--json <out.json>Also write the machine-readable report (repo, scannedAt, files, hits[], bySeam).
--seams S3,C1,P1Restrict to specific seams of the resolved corridor's catalog (ids are never shared between corridors).
--quietSuppress the human rendering (pair with --json).

Exit codes: 0 no error-severity hit · 1 at least one error-severity hit · 2 usage or scan failure. A clean scan is necessary but not sufficient — the exit criterion is a real-host smoke, plus a resume round-trip for log writers (leg A) and a real browser assertion for the client half (leg B).

The twenty legAB seams

Order follows the catalog in lib/scan.mjs (leg A first, then leg B), which is also the order test/card.test.mjs pins the card to.

IdSeverityWhat changed on the way to 0.1.5-rc.1
S3errorassistant/message gained a required stream field (session format V3): a log written without it imports successfully and then refuses to resume (Session.fromRestore throws invalid settlement fields).
S8errorSessionHandle.read() returns SessionHandleReadResult ({ eventState, events }) instead of the event array; array operations must unwrap .events.
S9errorSystemPrompt's config renamed persona → personaPrefix / personaSuffix. Substituting includeHarnessIdentity: false is not equivalent — it deletes the harness identity block.
M1errorThe local gate compiles a stale type line: dev/test types pinned at 0.1.5-alpha.*, or a tsconfig paths alias resolving to a missing checkout directory, makes TypeScript fall back silently to the published types. Green gate, wrong ruler.
S4errortool/code-dispatch was renamed tool/ptc-dispatch; the old label is no longer recognized in V3 sessions.
S5errorctx.agent was removed: the caller must pass the Agent explicitly (e.g. the second parameter of setup(agentCtx, agent)).
S6errorInbox is a type interface, not a constructable class; fixtures use the official unsupported shape and runtime code reads agent.inbox.
S7warnSubprocessHandle.pid was removed (only SubprocessTerminalHandle.pid remains); drop the field from test fixtures.
S2warnEpochHeader.system was removed: the system prompt is surface node 0's system/message now.
S1warnSession format V3 and generation-suffixed log names — the current generation is session.v3.jsonl.zstd, so scripts that hardcode session.jsonl.zstd fail silently.
S10warnPlugin-authored session events must go through the host's fail-closed adaptation gate: Session.append has no ignorable write channel, so an unconditional append can make a session unreadable.
C1errorThe bare client slot conversation was deleted and replaced by main + main.conversation, with no alias. ctx.slots.inject() only fires when the declaration exists, so a plugin targeting it stops mounting silently.
C2error@deepseek-ai/dsh-client-ui-sidebar-textpreview was renamed …-sidebar-documentpreview; the old name is gone with no shim package.
P1errorThe peer band must keep its second segment: >=0.1.2-rc.1 <0.2.0 alone rejects 0.1.5-rc.1 under npm semver's prerelease-tuple rule (measured false on semver 7.8.5).
C4warnrc.1 added a global main-panel model (main, sidebar.panellist, ctx.layout.selectPanel(MainPanelId | null)) and appended a usePanelInfo standard prop to almost every slot.
C5warnDocument preview moved to the keyed slot sidebar.right.tab.document (DocumentContent); sidebar.right.pane.tab survives but its parent entry became rightbar.session.
H1warnKNOWN_SESSION_EVENT_TYPES gained deliverables/presented and subagent/catalog — the fail-closed vocabulary grew.
H2warnThe new present tool's row occupies tool.call.toolview key 'present', which was free in alpha.1.
H4infoThe DeepSeek adapter's default advisory catalog now leads with deepseek-flash (DeepSeek-V41-Flash).
H3infoNew optional capabilities: ctx.sessionFeedback, ctx.layout.beginNavigation(), ctx.workspaces.openSession() / openWorkspace() / forkSession(). Listed on the card; deliberately not auto-detected.

S7, S2, S1, S10, C4, C5, H1, H2 and H4 are deliberately advisory: they have legitimate matches (a repo that already uses the new API, a documentation snapshot, a plugin's own model-id table, a Node ChildProcess.pid), so the scanner reports them as leads for manual review rather than failures. M1 and P1 are structured checks — they resolve package.json and tsconfig*.json instead of matching text — and H3 is card-only: documented, id-parity checked, and deliberately without a detector (CARD_ONLY = ['H3']).

The five legC seams (0.1.5-rc.2 → 0.1.6-alpha.2)

Order follows the catalog in lib/scan-0.1.6.mjs, which is also the order test/card.test.mjs pins the legC card to. Every seam here is error and every one is detected (CARD_ONLY = []).

IdSeverityWhat changed on the way to 0.1.6-alpha.2
E1erroragent/created listeners are dispatched serially: a listener that throws — or that does slow work — blocks agent creation outright. Wrap synchronous work in try/catch and defer the rest with queueMicrotask/setImmediate or your own queue.
E2errorAn async apply() whose first await precedes its registrations: anything registered afterwards lands in the unload window and throws INACTIVE_EFFECT, while the old closure keeps running. Register everything before the first await, inside one ctx.effect().
E3errorDeleted slot/state keys: settings.plugin.item became the keyed→list plugins.item, and SessionListState.current is gone — a settings card disappears silently (spec === undefined early return), and current casts keep compiling while the feature is dead.
E4errorDeleted client API: sessions.open / openSubagent / clear became retain / using / retainInfo.
E5errorDeleted model literals: deepseek-v4-flash* and deepseek-v4-vision-exp. The default model catalog shrank from 4 to 2, and an uncatalogued id passes through as text-only.

The same discipline applies as for legAB: a clean scan is necessary, not sufficient. legC breakage is silent or runtime-only (the published type line hides the deletions), so the exit criterion stays a real-host smoke on a temp DSH_HOME, plus the log-writer round-trip and the real-browser assertion where they apply.

What this does not cover

  • A hop past every corridor here. legAB ends at 0.1.5-rc.1 by construction: the harness hop 0.1.5-rc.1 → 0.1.5-rc.2 added no plugin-facing seam (this package's own dev/test pin now runs on the 0.1.7-rc.2 line, so the catalog is verified against those published types; the compat workflow's probe still anchors 0.1.6-alpha.2), and legC covers 0.1.5-rc.2 → 0.1.6-alpha.2. A later hop that adds a seam is not covered: a corridor is closed, and widening a card is worse than adding one. It gets a new card and a new index row — not a new package.
  • The 0.1.1 → 0.1.2 hop. Use the community convergence skill.
  • Restating across legs. Leg A owns the session-format seams (assistant/message.stream, SessionHandleReadResult, EpochHeader.system, ctx.agent, Inbox, SystemPrompt.persona, the V3 log generation) and leg B does not restate them — the whole packages/core/session/src diff in leg B's range is two added event-type literals and one comment line. Each leg's card section keeps its own scope statement.
  • The DSH user-facing upgrade path. This package upgrades plugin source code, not a user's harness installation.
  • Theme tokens. docs/web-styling.md has zero changes in leg B's range.
  • Proof. A clean scan is a hypothesis. The exit criterion is a real-host smoke (temp DSH_HOME, target CLI, plugin add <tarball>, --dump-config) plus a resume round-trip for session-log writers (leg A) and a real browser assertion for every client-side hit (leg B).

Security boundaries

  • Read-only scan. The CLI never writes inside the scanned repository; --json writes only to the path you pass.
  • No network, no shell. The scanner imports nothing beyond Node's standard library and never spawns a process.
  • No secrets. Nothing in the package reads credentials, environment tokens, or session data.
  • Sandboxed smoke recipe. The card's real-host check uses a mkdtemp DSH_HOME; it never touches your real ~/.dsh.

Development

npm install                        # or: pnpm install (the repo ships a pnpm-lock.yaml)
npm test                           # node --test: scanner, card<->catalog parity, real Cordis + SkillRegistry
npm run verify:self-contained      # every import resolves inside the package
npm run verify:artifacts           # the packed tarball carries the skill, CLI and patch, and excludes tests
npm run check:readmes              # five-language README consistency
npm pack

The scanner has a synthetic fixture pair per legAB leg: fixtures/leg-a-bad-repo (leg A's session/config seams, every error seam present on purpose) with fixtures/leg-a-good-repo (adapted), and fixtures/bad-repo (leg B's client-slot seams) with fixtures/good-repo (adapted) — plus a live negative on a family repository already pinned to 0.1.5-rc.1, so a regression in the catalog fails the suite rather than a downstream user. test/card.test.mjs asserts that each card's index and its own catalog (lib/scan.mjs for legAB, lib/scan-0.1.6.mjs for legC) name exactly the same seam ids with the same severities, that legAB's CARD_ONLY is exactly ['H3'] while legC's is empty, and that the two catalogs share no seam id — the evidence-binding rule as a machine gate, per corridor.

Topics

dsh, dsh-plugin, deepseek-harness, deepseek, cordis, plugin-upgrade, migration, skill, version-card, scanner, client-slots (mirror package.json keywords; dsh-plugin is the ecosystem's visibility channel).

PerryLink DSH Plugin Family

This project is one of the 45 DeepSeek Harness plugins maintained by PerryLink. If this one helps you, the others likely will too:

PluginOne-liner
dsh-auto-reviewSecond-model auto-review on the approval chain, fail-closed by default
dsh-autotierAutomatic strong/cheap model-tier routing with deterministic risk guards and a /tier command
dsh-background-agentsDurable background child agents with a Web UI sidebar, messaging and interrupt
dsh-budgetCost governance for DeepSeek Harness: budgets, carbon, and latency in one panel.
dsh-catalogDSH Desktop Market standard catalog source for the PerryLink family
dsh-cert-mcpRead-only MCP server exposing the certification registry: grades, snapshots and five-dimension evidence
dsh-checkpoint-rewindClaude Code /rewind-equivalent: snapshots, session forks, one-shot restore
dsh-claude-moveMigrate Claude Code sessions, memory, skills and CLAUDE.md into DSH
dsh-clickCross-platform native desktop control for DeepSeek Harness — Windows first.
dsh-composer-historyTerminal-style input history for the web composer: arrows, Ctrl+R search
dsh-data-qualityDataset quality checks and citation cross-checks (the optional numeric bridge consumed here)
dsh-defendPrompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness.
dsh-doublecheckEngineering-discipline guard: requirements grill, test gates, adversary review
dsh-drawUnified static-image generation routing for DeepSeek Harness.
dsh-fastRead-only performance diagnostics for DeepSeek Harness.
dsh-fund-researchDeterministic research reports for Chinese public mutual funds
dsh-githubGitHub PR/issues integration for DSH, every write gated by approval
dsh-industry-researchIndustry research orchestration that seals its deliverables through this plugin's ctx.researchReport.assemble
dsh-layaLaya typed decisions (noul/choice/score) as a first-class Cordis service and model-visible tools
dsh-libraryLocal document knowledge base for DeepSeek Harness.
dsh-local-aiLocal-model (Ollama) integration for DeepSeek Harness.
dsh-lsp-actionsLSP diagnostics, formatting, completion, code actions and rename over language servers
dsh-maskPII masking middleware: anonymize at the model boundary, restore at the display layer
dsh-mcp-panelRead-only MCP runtime panel: /mcp command + Settings tab with status, tools and errors
dsh-mementoApproval-gated cross-session memory: ctx.memory seam + SQLite + memory tool
dsh-observeOpenTelemetry and Langfuse observability exporter for DeepSeek Harness.
dsh-output-stylesClaude Code outputStyles-equivalent runtime style switching
dsh-permission-rulesClaude Code-style declarative allow/deny/ask permission rules with audit
dsh-plugin-certificationCommunity certification registry with repro-checkable grades and badges
dsh-plugin-doctorZero-dependency static + sandbox smoke detector for DSH plugins
dsh-plugin-guidePlugin-development knowledge base as an on-demand agent skill
dsh-plugin-kitShared zero-runtime-dependency toolkit for the PerryLink DSH plugins
dsh-plugin-upgradeOne-package, one-corridor-index plugin upgrade skill: routes a repository to the matching closed corridor card
dsh-plugin-upgrade-015Merged 0.1.3-alpha.1 → 0.1.5-rc.1 upgrade corridor card plus a zero-dependency seam scanner
dsh-reachMulti-channel approval/question bridge: WeChat/Telegram/Feishu, session console
dsh-research-reportVerifiable research-report engine: content-addressed evidence ledger and sealed versions
dsh-scoreMulti-dimensional quality scoring for DeepSeek Harness plugins.
dsh-session-pinPin sessions in the Web sidebar with durable ordering
dsh-session-syncCross-device session sync for DeepSeek Harness — a dedicated git mirror of your session store.
dsh-skill-pack-securitySecurity-audit skill pack: secret scan, dependency and supply-chain review
dsh-talkVoice-first session loop for DeepSeek Harness: talk to it, hear it answer.
dsh-team-roomsCross-session team rooms: shared message bus, task board and timeline
dsh-test-driveIsolated install-and-smoke test drives for DeepSeek Harness plugins.
dsh-ticktickTickTick/Dida365 task bridge: session-header panel + 11 tools
dsh-translateVendor parameter translation and deterministic JSON repair for DeepSeek Harness.

License

Apache-2.0 — see LICENSE. Install-time dependencies and their licenses are listed in THIRD_PARTY_NOTICES.md; nothing is bundled.

Comments

Loading…

Similar plugins

dsh-auto-update

by a1113622001

DeepSeek Harness (cordis) plugin: self-update for the harness launcher - checks npm for a newer @deepseek-ai/dsh, stages it, and applies it on harness exit (or update-and-restart from the web panel).

Development & InfrastructureTerminal & ClientsManifest valid

★ 3

MIT

JavaScript

Aug 22, 2026

dsh plugin --profile web add dsh-auto-update

by HubaKing

DeepSeek Harness (dsh) plugin: registers a global skill that teaches agents how to discover, evaluate and install community plugins from the GitHub dsh-plugin topic, dshmarket and npm. | DSH 社区插件生态指南

Development & InfrastructureManifest valid

★ 5

MIT

JavaScript

Sep 10, 2026

dsh plugin --profile web add @hubaking/dsh-community-plugins

by PerryLink

Security-audit skill pack + plugin_vet supply-chain gate for DeepSeek Harness (dsh): 8 bilingual agent skills (secret scan, dependency audit, supply-chain review, prompt-injection review, audit orches

Manifest valid

★ 16

Apache-2.0

TypeScript

Sep 25, 2026

dsh plugin --profile web add dsh-skill-pack-security

by ymh0000123

DeepSeek Harness 插件:检测 DSH / @deepseek-ai npm 包与 GitHub 源插件的更新,设置页给出详细表格,并支持带显式构建授权的一键更新。A DSH plugin that detects updates for installed DSH/@deepseek-ai npm packages and GitHub-sourced plugins, with

Manifest valid

★ 0

MIT

JavaScript

Aug 17, 2026

dsh plugin --profile web add dsh-update-checker

by PerryLink

Corridor folded into dsh-plugin-upgrade 2.0.0 (never published under this name): its 0.1.5-rc.2 -> 0.1.6-alpha.2 card and E1-E5 scanner live in that package now.

Tools & CapabilitiesManifest valid

★ 0

Apache-2.0

JavaScript

Sep 19, 2026

dsh plugin --profile web add dsh-plugin-upgrade-016

Preflight checks for a DeepSeek Harness plugin before submitting it to the community list: verifies the dsh.bundle manifest, cordis.patch.yml wiring, client bundle shape, and peer ranges that silently

Development & InfrastructureTools & CapabilitiesManifest valid

★ 0

dsh plugin --profile web add dsh-plugin-preflight