Introduction¶
The DeepSeek Harness ecosystem allows expanding tool capabilities through plugins. In automated release processes, manually reviewing changed files and metadata can easily miss risks. The DSH Release Guardian plugin performs local scanning of Git changes and provides deterministic release risk assessment and quality gating.
Plugin Positioning¶
This plugin is maintained by XiaoSong1223 and is a local, deterministic release risk checking tool. It can scan Git changes, discover test, type-check, and build commands for common projects, and generate reports.
Core Features¶
- Change Scanning: Supports scanning Git changes in a worktree, staged changes, or a specified scope.
- Rule Application: Applies deterministic rules to metadata and added lines in changed files.
- Command Discovery: Automatically discovers test, type-checking, and build commands for JavaScript, Python, Go, Rust, Java, and .NET projects.
- Report Output: Supports generating human-readable reports or versioned JSON reports.
- DSH Integration: Registers the
release_guardian_checktool in DeepSeek Harness. - Ecosystem Compatibility: Provides an optional Codex skill adapter and a Claude Code plugin, including the release-guardian skill, release-auditor subagent, dsh-release-guardian command, and pre-commit gating.
Installation and Enablement¶
- Download the plugin package.
- Install it to a DSH profile.
curl -LO https://github.com/XiaoSong1223/dsh-release-guardian/releases/download/v0.1.0/dsh-release-guardian-0.1.0.tgz
npx @deepseek-ai/dsh@0.1.0-rc.6 plugin --profile headless add ./dsh-release-guardian-0.1.0.tgz
Typical Usage¶
- CLI Usage:
dsh-release-guardian --help - DSH Bundle Installation:
npx @deepseek-ai/dsh@0.1.0-rc.6 plugin --profile headless add ./dsh-release-guardian-0.1.0.tgz
Applicable Scenarios and Cautions¶
- Security Model: Default check operations are read-only and do not execute project code. Project checks require explicit authorization (CLI requires
--run-checks, DSH requiresaction: "run"). - Permissions: Approved commands do not run inside a sandbox and use the invoking user’s permissions.
- Environment Requirements: Requires Node.js ^22.19.0 or >=24.0.0.
- License: MIT.
Conclusion¶
It is a risk signal in release processes rather than absolute proof. After installation, it can be integrated into workflows. For the related directory and source code, see: DeepSeek Harness Plugin Directory and GitHub Repository.