dsh 项目与 profile 的依赖供应链卫生审计:peer 范围可解析性、坏 dist-tag 检测(#2763 类)、过期/缺许可证/非注册表来源依赖与安装版本漂移——CLI + agent 可调用 dep_audit 工具。
安装
# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)
dsh plugin --profile web add github:zoahdev/dsh-dep-audit
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。
README
Dependency supply-chain hygiene audit for DeepSeek Harness (dsh) projects and profiles.
It answers: “can I trust the dependency graph of this dsh plugin / profile?” — peer ranges that resolve to nothing, dist-tags that contradict declared ranges, stale or unlicensed dependencies, non-registry sources, and installed versions that silently drifted from what package.json declares.
Complements the rest of the zoahdev security suite:
| Tool | Focus |
|---|---|
| dsh-poison-guard | malware / obfuscation scan of plugin code |
| dsh-plugin-doctor | publish readiness: manifest/patch/build/pack/install |
| dsh-dep-audit | dependency graph hygiene: resolvability, dist-tags, staleness, sources, licenses, drift |
Install
dsh plugin add dsh-dep-audit
Or run it standalone without installing into dsh:
npx dsh-dep-audit .
Checks
| Check | What it verifies | Status when triggered |
|---|---|---|
manifest |
package.json exists, parses, declares name / version |
fail |
peer-resolvable |
every peerDependencies range matches at least one published version on the registry |
fail |
dist-tag |
dist-tags.latest does not contradict a declared range (the broken-latest / ERESOLVE class, e.g. discussion #2763) |
warn |
source |
audited dependencies use registry specifiers, not git: / file: / link: / workspace: |
warn |
license |
registry dependencies declare a license in their latest published metadata | warn |
freshness |
registry dependencies have a release within the last 365 days (configurable) | warn |
drift |
installed versions in node_modules satisfy the declared ranges (ERESOLVE / host-shadowing class) |
fail |
outdated |
installed versions are not behind the registry latest |
warn |
ok is true only when every check passes (no fail items). Warnings are real signals but not blockers.
CLI
dsh-dep-audit [dir] [options]
--json print the machine-readable report
--offline skip registry network calls
--all include devDependencies
--registry <url> npm registry base URL (default: NPM_CONFIG_REGISTRY or registry.npmjs.org)
--stale-days <n> warn when latest release is older than n days (default 365)
--help show help
Exit codes: 0 all pass, 1 at least one fail, 2 usage/IO error.
npx dsh-dep-audit . --json
npx dsh-dep-audit ~/.dsh/profiles/web --offline
In-harness usage (agent-callable)
After install, ask your dsh agent:
审计一下当前插件的依赖健康:
dep_audit,目录指向项目根目录。 Run a dependency audit on this plugin:dep_auditwithdirset to the project root.
The agent calls the dep_audit tool (dir, optional options), which returns a dsh-dep-audit/v1 report:
{
"schema": "dsh-dep-audit/v1",
"target": ".",
"offline": false,
"ok": true,
"summary": { "total": 8, "pass": 8, "warn": 0, "fail": 0 },
"checks": [ ... ]
}
Examples
Audit a profile without network access:
npx dsh-dep-audit ~/.dsh/profiles/web --offline
Gate CI on dependency hygiene:
- run: npx dsh-dep-audit .
Why it exists
- pnpm can silently link an older RC into a plugin's peer slot; “loads fine” ≠ “matches the declared peer range”.
driftturns that precondition into a checked fact. - The npm
latestdist-tag can point at an old, broken build whilenexthas the real release —dsh plugin add <name>then resolves something unexpected for everyone.dist-tagflags the contradiction before it bites (the discussion #2763 failure class). - A dependency whose latest release is years old, or that lacks a license, is a red flag in a supply chain that grows by thousands of plugins per week.
- An unlicensed or stale dependency is not malware — that is poison-guard's job. This plugin is the “healthy diet” half of the supply-chain story.
Report envelope
Every check carries { id, status, title, detail, items }; items are { name, issue, level } with level: warn | fail. The schema version (dsh-dep-audit/v1) is stable and machine-readable for CI.
Development
pnpm install
pnpm typecheck
pnpm build
pnpm test
pnpm test:integration
CI runs the dsh-plugin-doctor preflight, unit tests, a packed-artifact integration that installs the real tarball and invokes the real dep_audit handler, and a fresh-profile dsh web boot smoke on Windows.
License
MIT © 2026 zoahdev
dsh-dep-audit(中文)
DeepSeek Harness(dsh)项目与 profile 的依赖供应链卫生审计。
回答一个具体问题:“这个 dsh 插件 / profile 的依赖图能信吗?” —— peer 范围在注册表上解析不到、dist-tag 与声明的范围互相矛盾、依赖长期不更新或没有许可证、用了 git/file/workspace 来源,以及安装版本与 package.json 声明悄悄漂移。
与 zoahdev 安全套件的分工:
| 工具 | 定位 |
|---|---|
| dsh-poison-guard | 插件代码的恶意/混淆扫描 |
| dsh-plugin-doctor | 发布就绪:manifest/patch/build/pack/install |
| dsh-dep-audit | 依赖图卫生:可解析性、dist-tag、过期、来源、许可证、漂移 |
安装
dsh plugin add dsh-dep-audit
不装进 dsh 也能单独用:
npx dsh-dep-audit .
检查项
| 检查 | 验证内容 | 触发级别 |
|---|---|---|
manifest |
package.json 存在、可解析、有 name / version |
fail |
peer-resolvable |
每个 peerDependencies 范围在注册表上至少有一个已发布版本 |
fail |
dist-tag |
dist-tags.latest 不与声明范围矛盾(坏 latest / ERESOLVE 一类,见 讨论 #2763) |
warn |
source |
依赖使用注册表来源,而非 git: / file: / link: / workspace: |
warn |
license |
注册表依赖的最新元数据声明了许可证 | warn |
freshness |
注册表依赖在 365 天内有新发布(可配置) | warn |
drift |
node_modules 里的实际版本满足声明范围(ERESOLVE / 宿主遮蔽类) |
fail |
outdated |
已安装版本不落后于注册表 latest |
warn |
只有所有检查都没有 fail 项时 ok 才为 true。warn 是真实信号,但不是硬阻塞。
CLI
dsh-dep-audit [dir] [options]
--json 输出机器可读报告
--offline 跳过注册表网络请求
--all 把 devDependencies 也纳入审计
--registry <url> npm 注册表地址(默认 NPM_CONFIG_REGISTRY 或 registry.npmjs.org)
--stale-days <n> 超过 n 天未发布即告警(默认 365)
--help 帮助
退出码:0 全过,1 有 fail,2 用法/IO 错误。
npx dsh-dep-audit . --json
npx dsh-dep-audit ~/.dsh/profiles/web --offline
在 harness 内使用(agent 可调用)
装好后对 agent 说:
审计一下当前插件的依赖健康:
dep_audit,目录指向项目根目录。
agent 会调用 dep_audit 工具(dir,可选 options),返回 dsh-dep-audit/v1 报告:
{
"schema": "dsh-dep-audit/v1",
"target": ".",
"offline": false,
"ok": true,
"summary": { "total": 8, "pass": 8, "warn": 0, "fail": 0 },
"checks": [ ... ]
}
为什么需要它
- pnpm 可能把旧 RC 静默链进插件的 peer 槽;“能加载”≠“符合声明的 peer 范围”。
drift把这条前置条件变成可核验的事实。 - npm 的
latestdist-tag 可能指向旧坏包,而next才是真版本——dsh plugin add <name>会让所有人解析到意外结果。dist-tag在踩坑前先标出矛盾(讨论 #2763 的失败类别)。 - 最新版本几年没动、或没有许可证的依赖,在以每周千计增长的插件供应链里都是红旗。
- 没许可证、长期不更新不等于恶意——那是 poison-guard 的事。本插件负责供应链“健康饮食”这一半。
报告结构
每个检查带 { id, status, title, detail, items };items 是 { name, issue, level },level 为 warn | fail。schema 版本 dsh-dep-audit/v1 稳定、可给 CI 解析。
开发
pnpm install
pnpm typecheck
pnpm build
pnpm test
pnpm test:integration
CI 跑 dsh-plugin-doctor 预检、单元测试、打包集成(真实安装 tarball 并调用真实 dep_audit handler)、以及 Windows 上全新 profile 的 dsh web 启动冒烟。
许可证
MIT © 2026 zoahdev
Related ecosystem tools
- dsh-dep-audit - dependency supply-chain hygiene
- dsh-quality-score - plugin quality scorecard + full-registry leaderboard
- dsh-ecosystem - health scan, impact, trend, live dashboard
- dsh-tutorials - bilingual plugin pipeline tutorials
FAQ
- How do I install? dsh plugin add dsh-dep-audit or run the CLI directly (see README).
- Does it need an API key? No.
- Is it read-only? Yes by default; any write/apply is an explicit flag.
链接
同类插件
yjh051108/dsh-routing-suite★ 7000
一个仓库三件套:DSH 插件包的运行时注入器(注入、热重载、卸载、开发侧挂区一键转正、路由自愈,外带设置页插件管理:列出、卸载、拖入文件夹内化)、任务感知的思维模式路由 agent 预设(router-standard / router-spec / router-react)、以及分级两级任务协议(commit_star / lock_stage / revise_do / edit_plan / mark_task / redteam_verdict 六个工具,任务状态落盘)。注入器实现直接在库内,安装的是它自己的行为而不是一份依赖清单。
strukto-ai/mirage#dsh★ 3678
把文件系统与 bash 提供者换成 mirage 虚拟工作区:文件工具与 shell 命令作用于挂载的资源(RAM、S3、Redis、Slack、Gmail、Notion、Postgres)而非宿主磁盘,支持按挂载点设置读/写/执行模式、按命令选择沙箱(进程内 monty、pyodide、quickjs;远程 docker、e2b、daytona),并可在虚拟终端中安装 CLI(git、gh、slack、linear、ntn、gws,或自行注册的程序树)作为命令头词。
hust-open-atom-club/oh-dsh★ 324
社区发行版:TUI、桌面端与 Web UI 统一体验,分层安装、一步到位。
weijiafu14/pi2dsh★ 212
Pi Host ABI 兼容引擎:装一次之后,npm 上的 Pi 扩展原包经 `dsh plugin add <pi-package>` 直接作为 DSH 原生插件挂载。已在官方 DSH 上端到端验证 pi-mcp-adapter(完整 MCP 管理面:OAuth、resources、prompts、MCP Apps、elicitation、sampling)、@tintinweb/pi-subagents、pi-code、pi-hermes-memory、pi-background-tasks;`pi2dsh inspect` 在安装前报告一个包的兼容情况。
Fishquito7/dsh-skill-mcp-panel★ 175
在 DSH Web 设置中管理技能与 MCP 服务器:技能卡片热启停、工作区作用域、分组、批量迁移与拖拽导入,以及 stdio/HTTP MCP 增删改查、连接测试、密钥脱敏,并附带统一 dsh-panel 命令行。
lire1131/dsh-undo-savepoint★ 172
DSH 撤销/回退系统:配置变更自动存档,一键撤销/恢复/回退到任意版本,支持 WebUI 与离线 CLI/GUI 工具(DSH 启动失败也能救)。
社区评论
评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。