Introduction

In the DeepSeek Harness (DSH) web client development workflow, frequently managing Git branches inside the chat interface is a common pain point. Developers often need to leave the conversation interface and run git checkout or git stash in a terminal, which breaks their flow. The dsh-git-status plugin integrates real-time status display and switching directly into the Composer tool row of DSH Web, bringing branch management back into the conversation context.

Plugin Overview

This is a plugin for the DSH Web client, maintained by weiyuou-chowbus. Its core value lies in localizing and securing Git status awareness and branch switching, providing a lightweight entry point for developers to interact with code repositories.

Core Features

  • Real-time branch indicator: Displays a chip for the current branch on the right side of the Composer toolbar, polling status every 3 seconds. The chip includes a dot indicating whether the workspace is clean (a dirty state is shown when uncommitted changes exist).
  • Workspace awareness: The plugin follows the current session’s working directory (cwd). When you switch the DSH session workspace, the indicator automatically updates to the current branch of the corresponding directory.
  • Branch switching: Clicking the indicator opens a filterable list, showing all local branches (sorted by latest commit and including upstream tracking info). Clicking a target branch opens a confirmation dialog.
  • Dirty-state safety: This is an important safety feature of the plugin. If the workspace has uncommitted changes, checkout operations are blocked by default. The plugin provides an explicit “Stash & switch” action, automatically running git stash push --include-untracked before switching and restoring the stash if the switch fails, preventing code loss.
  • Secure design: The plugin uses a “shell-free” invocation method, with all Git commands executed via child_process.execFile. All paths are resolved with realpath at request time, accepting only registered workspace paths or the configured repoPath. Branch names are limited to the results of local branch enumeration, and input is not processed via shell escaping.

Installation and Enablement

To install this plugin, the system must have a configured DSH Web profile and pnpm in the system PATH.

dsh plugin --profile web add dsh-git-status

After installation, restart the web service to load the new plugin:

npm exec @deepseek-ai/dsh web

Configuration and Usage

By default, the plugin uses the current working directory of the DSH process as the repository path. If you want to specify a default repository for sessions without a workspace, you can override it via the config file.

Edit ~/.dsh/profiles/web/cordis.patch.yml and add or modify the following configuration:

- id: git-status
  config:
    repoPath: /absolute/path/to/your/default/repo

The plugin exposes the following HTTP endpoints:
* GET /git-status?cwd=<workspace path>: Gets the current branch, dirty state, and local branch list.
* POST /git-checkout: Switches branches; valid only for POST requests and requires confirmation.

Notes

  • Dependency requirements: The DSH Web profile and pnpm in PATH are required.
  • Path requirement: The repoPath configuration value must be an absolute path.
  • Interactive confirmation: All switching operations (checkout) require user confirmation and are POST-only.
  • Dirty-state handling: Dirty states are blocked by default. Branch switching in a dirty workspace only occurs if stash: true is explicitly enabled or the “Stash & switch” button in the UI is used.
  • Security principles: The plugin does not use Shell to execute commands; all input is validated against a whitelist, making it suitable for development environments with strict security requirements.

Conclusion

dsh-git-status addresses the pain point of managing code state within the conversation flow by embedding lightweight Git operations into the DSH Web interface. It provides intuitive visual feedback while ensuring operational safety through strict whitelist validation and dirty-state protection mechanisms. You can view the source code or submit feedback via the GitHub repository.