DeepSeek Harness (DSH) uses a plugin-based architecture. When maintaining a DSH instance, manually updating the core CLI or dependencies can easily cause service interruptions due to version mismatches or file locking issues. The dsh-autoupdate plugin solves this problem through a protected update pipeline, ensuring that the update process is safe and controllable.

Plugin Positioning

dsh-autoupdate is a built-in auto-update plugin for DeepSeek Harness. It was developed by maintainer lc23313 and is released under the MIT license. The plugin provides a manual check entry on the settings page and implements a complete update transaction protection mechanism, including health checks, automatic rollback, and a circuit-breaker-based degradation strategy.

Core Features

  • Settings Page UI: Adds an “Check for Updates” button on the DSH settings page, with a confirmation dialog to trigger the update process.
  • Protected Update Pipeline: Uses an “apply on exit” mechanism. The daemon performs installation after the DSH process exits, avoiding file locking issues in Windows environments.
  • Precise Version and Validation: Locks the exact version during installation and confirms successful updates through dual validation (manifest version + binary execution validation).
  • Automatic Rollback: If any failure occurs during the update process, the system automatically rolls back to the previous version.
  • Circuit Breaker and Degradation: Includes a built-in circuit breaker that automatically degrades the mode from auto -> notify -> off based on consecutive failures.
  • Arbitrary Dist-Tag Support: Supports tracking any npm dist-tag (such as latest, rc, etc.).

Installation and Enablement

Install through the official plugin channel:

dsh plugin --profile web add dsh-autoupdate

After installation, restart the DSH process to activate the plugin. You can verify whether the plugin has been registered using the following command:

dsh --dump-config --profile web

Typical Usage

After installation, the plugin initializes automatically. Status and log files are located at:
$DSH_HOME/plugins-data/dsh-autoupdate/

Common commands to view the current status and logs:

cat $DSH_HOME/plugins-data/dsh-autoupdate/state.json
cat $DSH_HOME/plugins-data/dsh-autoupdate/autoupdate.log

Security and Trust

The plugin is designed with security as a priority:
* Minimal Privileges: Only generates npm commands (version queries and global installation) and optional dsh plugin commands.
* Isolated Writes: Never writes to DSH-owned files (such as settings.yaml or configuration files).
* Audit Logging: All decision processes are recorded in autoupdate.log for easy auditing.
* Version Locking: The installation process always locks the exact version resolved at check time.

Dependency Requirements

Using this plugin requires the following environment conditions:
* Node.js >= 18
* @deepseek-ai/cordis >= 4.0.0
* @deepseek-ai/schemastery >= 1.0.0