Bundle
dsh-profile-lock-proof
Content-addressed proof that a DeepSeek Harness profile declaration, pnpm lock and installed bundles agree
- Source
- dongsheng123132
- stars
- 2 stars
- License
- MIT
- Updated
- Updated 10 days ago
Readme
# dsh-profile-lock-proof [](https://github.com/dongsheng123132/dsh-profile-lock-proof/actions/workflows/ci.yml) [](LICENSE) [](package.json) [](https://github.com/dongsheng123132/awesome-dsh-plugins#2origin-plugin-lab) `dsh-profile-lock-proof` produces a content-addressed, machine-readable proof that a DeepSeek Harness profile's dependency declaration, pnpm lock importer, installed package manifests, and each package's declared `dsh.bundle.patch` agree. It is deliberately narrower than an SBOM, CVE scanner, signature verifier, or installer. It does not execute packages, contact the network, mutate a profile, or return manifest, lockfile, patch, script-command, or secret contents. Version 0.2.0 removes the bundled DSH tool runtime and the default export that stock Cordis Loader misclassified. The bundle now exposes host-neutral tool definitions through its namespace export; local-path and fixed-commit installs are exercised against the real stock Web profile. ## Proof boundary - Input paths are workspace-relative regular files; traversal and symlinks are rejected. - Profile and lockfile bytes must match the SHA-256 values in an explicit proof manifest. - Dependency specifiers must be exact semver or `github:owner/repo#<40-hex-commit>`. - The pnpm importer specifier, installed name/version/package hash, bundle patch path/hash, and absence of lifecycle hooks must all agree. - Missing, stale, invalid, mutable, mismatched, or lifecycle-script-bearing evidence fails closed. - Output contains identities, classifications, hashes, status, and disclosure only. Reports are written atomically under an explicit `artifactDir` and read back. ## CLI ```bash dsh-profile-lock-proof inspect --workspace . --manifest proof.json dsh-profile-lock-proof verify --workspace . --manifest proof.json --artifactDir artifacts ``` Exit `0` means a verified proof, `2` means verification or input failure. ## DSH / MCP tools - `dsh_profile_lock_inspect` - `dsh_profile_lock_verify` - MCP aliases: `profile_lock_inspect`, `profile_lock_verify` The MCP surface is deliberately lower privilege: it accepts bounded inline evidence only, never reads or writes files, and shares the validation core. DSH/CLI may write only to an explicit workspace-relative `artifactDir`, atomically and with read-back verification. Install into an isolated profile: ```bash dsh plugin --profile profile-lock add github:dongsheng123132/dsh-profile-lock-proof#<commit> ``` ## Development ```bash npm ci npm test npm run check npm run smoke:plugin npm run smoke:mcp npm run smoke:web-loader # requires DSH_CHECKOUT and isolated DSH_HOME ``` MIT licensed. See [SECURITY.md](SECURITY.md) for the threat boundary.
Install
dsh plugin --profile web add github:dongsheng123132/dsh-profile-lock-proof#503407c6537791f2fa2a060fd8d126535538e977
Profile: web
With the hub plugin installed, ask your agent to install it by name — it resolves the same plan shown here.
dsh plugin --profile web add github:stvlynn/dsh.fish#path:packages/dsh-plugin-hub
install dsh-profile-lock-proof from the hub