All plugins

DSH / BUNDLE / CLIENT-UI

dsh-update-copilot

v0.8.0hezhongtang / dsh-update-copilot2a38226837

InstallableBundlesUI & client pluginsCommunity · Topic auto-analysisWeb UI

Overview

dsh-update-copilot

Update copilot for DeepSeek Harness: tracks the DSH core, bundled packages, and every installed plugin across npm and git, merged package-centric over all profiles, with one-click updates for eligible profiles. · DSH 更新助手:追踪 dsh 本体、bundle 包和所有已装插件(npm 与 git 双通道,跨 profile 按包合并),仅对符合条件的 profile 一键更新。

README / EN

Package documentation

Registry summary

Update copilot for DeepSeek Harness: tracks the DSH core, bundled packages, and every installed plugin across npm and git, merged package-centric over all profiles, with one-click updates for eligible profiles. · DSH 更新助手:追踪 dsh 本体、bundle 包和所有已装插件(npm 与 git 双通道,跨 profile 按包合并),仅对符合条件的 profile 一键更新。

dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.

Read the full README on GitHub

LIMITATIONS

Known limitations

- Plugin hot reload is phase-1 scoped: it covers updates whose running profile entry still exists and whose new version keeps the same `dsh.bundle.patch` and `dsh.client` declaration (this includes `link:` checkouts — node_modules points at the checkout through a symlink, so the pull takes effect on the same files the reloader reads). Bundle-patch changes, non-current profiles, and copilot self-update still ask for a `dsh` restart. - `link:` updates require the checkout to have an upstream branch configured; uncommitted changes are auto-stashed and restored after the pull, and a failed restore (stash pop conflict) needs manual `git stash list` / `git stash pop`. - Switching a `link:` to a remote source breaks the local link and there is no automatic switch back (the spec must be edited by hand). The npm-first strategy installs the registry version, which may differ from your local development checkout. - Unauthenticated GitHub API is rate-limited (60 req/h) — briefs degrade gracefully to version lists. - Raw `git+https://` specs are reported as-is without a comparison channel. - The host export check is static named imports: dynamic `import()`, APIs only reached at runtime, and `import * as ns` are not flagged. Official `@deepseek-ai/*` packages are skipped. The target pass only packs `@deepseek-ai/dsh-*` at the DSH version line; a failed pack or an independently versioned package (`cordis`, `schemastery`) is skipped rather than reported as incompatible. - The peer-range check covers the common range forms (caret, tilde, intervals, unions, wildcards, exact) with node-semver's prerelease rule; exotic range syntax reads as "cannot evaluate" and stays silent. History snapshots are best-effort — an unwritable history directory means no rollback suggestion, never a blocked update.