Introduction¶
In the plugin ecosystem of DeepSeek Harness (DSH), dependency management is the foundation for building reliable agents. License compliance of open-source components directly affects the commercial feasibility of a project. Strong copyleft licenses such as AGPL-3.0, if mixed into a closed-source project, can lead to source code disclosure. The dsh-license-guard plugin aims to solve this problem by providing scanning, normalization, and compliance validation capabilities.
Feature Overview¶
The plugin scans all dependencies under the node_modules directory, normalizes their license identifiers into SPDX format, and categorizes them by type, such as permissive, weak copyleft, and strong copyleft. It supports blocking non-compliant dependencies according to a policy before release.
Installation and Enablement¶
Run the following command in the terminal to install the plugin:
dsh plugin add github:uckkk/dsh-license-guard
After installation, add "dsh-license-guard" to the DSH profile configuration file (for example, dsh.profile.bundles in package.json) to enable it.
Usage¶
The plugin provides two core tools.
Inspect License Composition¶
Run a scan first to inspect the license distribution of project dependencies:
license_scan(root="/workspace")
Perform Compliance Validation¶
Run a gate check before release and specify the license types that are prohibited:
license_check(root="/workspace", deny=["AGPL-3.0"])
Default Policy¶
The plugin includes a default policy:
* Permissive licenses (MIT, Apache-2.0, ISC, BSD, 0BSD, Zlib, Unlicense, CC0-1.0, etc.): allowed by default.
* Strong copyleft licenses (GPL-3.0, AGPL-3.0, SSPL-1.0, GPL-2.0, etc.): denied by default.
* Unknown/unlicensed licenses: counted as violations by default, and can be ignored via the parameter includeUnknown: false.
Technical Notes and Precautions¶
- Implementation: Pure Node.js implementation, with no network connection or external services required.
- Data source: Identification is based on the
licenseorlicensesfield in each dependency package’spackage.json; entries that cannot be identified are marked as “Unknown.” - Compliance nature: This is heuristic compliance screening and cannot replace professional legal advice. Before formal commercial use or release, be sure to obtain a legal review.
- Running permissions: The plugin runs with the permissions of the DSH process; review the source code yourself.
Summary¶
dsh-license-guard provides a complete closed loop from scanning to validation, helping developers avoid open-source license risks.