面向自建 Gitea / Forgejo 的只读工具,走两者共用的 REST API:实例信息、仓库列表、议题与 PR 搜索和读取、PR diff 与变更文件,以及 Actions 运行、任务与任务日志。工具元数据支持英文、繁体中文、简体中文与日文。
安装
# npm 包(预构建)
dsh plugin --profile web add @maxhsu/dsh-forge
# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)
dsh plugin --profile web add github:maxmilian/dsh-forge
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。
README
该插件的 README 只有英文版本。
Read-only DeepSeek Harness tools for self-hosted Gitea and Forgejo instances. The plugin uses the REST API shared by both projects and adds repository, issue, pull request, and Actions context directly to DSH.
DeepSeek Harness is in developer preview. This plugin is tested with
@deepseek-ai/dsh-tools 0.1.7-rc.2, retains compatibility with the0.1.0prereleases fromrc.6, and may need updates when Harness APIs change.
Features
- Inspect the configured instance version.
- List repositories owned by the authenticated user.
- Search issues and pull requests across visible repositories.
- Read an issue or pull request by repository and index.
- Read pull request diffs and changed-file metadata.
- List repository Actions runs and jobs, then read plaintext job logs.
- Localize runtime tool metadata in English, Traditional Chinese, Simplified Chinese, or Japanese.
- Forward cancellation and enforce request time and response-size limits.
- Keep every v0.3 tool read-only and safe for parallel execution.
Install
From a local checkout:
dsh plugin --profile web add .
dsh --profile web --dump-config
dsh --profile web
From npm (recommended):
dsh plugin --profile web add @maxhsu/dsh-forge
From the prebuilt release tarball:
dsh plugin --profile web add https://github.com/maxmilian/dsh-forge/releases/latest/download/dsh-forge.tgz
The tarball includes compiled JavaScript and declarations, so installation does not run a local TypeScript build. To track the repository instead:
dsh plugin --profile web add github:maxmilian/dsh-forge
Git installations run the package prepare script. pnpm 10 may ask you to allow that build in the
profile's pnpm-workspace.yaml; review and pin the source commit before allowing install-time code.
A published npm package or prebuilt tarball does not need that build permission.
Configure
Environment variables are preferred so the access token does not live in cordis.patch.yml:
export DSH_FORGE_URL='https://code.example.com'
export DSH_FORGE_TOKEN='replace-with-a-read-only-token'
dsh --profile web
DSH_FORGE_URL may include a subpath, such as https://example.com/git. The client preserves that
path when appending /api/v1. Public endpoints work without a token, but repository tools normally
need one.
The plugin can load before these variables are set. If a Forge tool is called without a configured URL, it returns an actionable configuration error instead of preventing the DSH profile from booting.
The profile patch can override runtime limits or provide credentials directly:
- id: forge-tools
name: dsh-forge
config:
baseUrl: 'https://code.example.com'
token: '' # Prefer DSH_FORGE_TOKEN. This field is marked secret in the config schema.
locale: en # en, zh-TW, zh-CN, or ja
requestTimeoutMs: 30000
maxResponseBytes: 1000000
Use the narrowest token scopes your instance supports. Version 0.3 never creates, updates, merges, reruns, or deletes remote resources.
locale controls model-facing tool descriptions, parameter help, and pending-call titles. English
is the default; Traditional Chinese, Simplified Chinese, and Japanese are included without external
translation services.
Tools
| Tool | Purpose |
|---|---|
forge_instance_info |
Read instance version information |
forge_list_repositories |
List repositories owned by the authenticated user |
forge_search_issues |
Search issues or pull requests across repositories |
forge_get_issue |
Read one issue |
forge_list_pull_requests |
List repository pull requests |
forge_get_pull_request |
Read one pull request |
forge_get_pull_request_diff |
Read one pull request as a unified diff |
forge_list_pull_request_files |
List files changed by one pull request |
forge_list_action_runs |
List repository Actions runs |
forge_list_action_jobs |
List jobs belonging to one Actions run |
forge_get_action_job_logs |
Read the plaintext log for one Actions job |
List endpoints clamp limit to 50 to keep model context bounded. API errors include the operation
and HTTP status but never retain request headers or credentials.
Development
Node.js 22 or newer and Bun are required for development:
bun install
bun run lint
bun run typecheck
bun run test:coverage
bun run build
bun pm pack --dry-run
Unit tests mock fetch. The Integration GitHub Actions workflow additionally starts disposable,
official Gitea and Forgejo containers and their Actions runners. It creates real repositories,
issues, branches, pull requests, workflow runs, and job logs before exercising the plugin client.
Compatibility verification
| Target | Verification |
|---|---|
| DeepSeek Harness | Local bundle install, composed-config dump, and boot smoke test |
| Gitea | Live CI against the official Gitea 1.27 container and Gitea Runner 3.1.0 |
| Forgejo | Live CI against the official Forgejo 16 container and Forgejo Runner 13.0.0 |
API payloads are returned as canonical JSON so fields added by either project remain available without requiring a plugin release. Diff and log responses remain plaintext to avoid JSON escaping.
Current scope
The plugin deliberately uses the common REST endpoints instead of instance-specific extensions. Actions availability depends on the server version and whether Actions is enabled. A future release can add approval-gated writes, pull-request reviews, artifacts, and webhook-driven workflows.
License
Contributions are welcome. See CONTRIBUTING.md for the development workflow and SECURITY.md for private vulnerability reporting.
链接
同类插件
zhu1090093659/dsh-web#packages/dsh-git-graph★ 8597
输入框上方提供 Git 分支选择器,并把分支泳道与提交历史画成图谱,沿着时间线找到任意变更。
Akimiya-z/codex-guard#dsh★ 136
在 DeepSeek Harness 内做提交前的 Pull Request 卫生检查:扫描当前改动中的 TODO 残留、硬编码密钥与非规范提交信息。
Cerbur/clutch-dsh#clutch-dsh-worktree★ 33
为 DSH Web UI 增加按 Git Worktree 组织 Session 的视角,同时继续由 DSH 管理原始 Project 和 Session 数据。
lehhair/dsh-diff-viewer★ 26
PiUI 风格 diff 查看器,替换 write/edit 工具调用的默认 DiffBlock。
DamonKoy/dsh-web-ui#dsh-git-graph★ 23
dsh web GUI 会话头部栏的 Git 分支选择器与提交图。
PerryLink/dsh-github★ 22
官方级 GitHub CI 集成:composite action.yml、轮询 PR 评审机器人(幂等行内评论 + status-check 门禁)以及 PR/issue 工具,所有写入走人工审批门。
社区评论
评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。