Introduction¶
DeepSeek Harness allows capabilities to be extended through plugins. In repository security, common static scanning tools often only produce results, making it difficult to trace their origin or prove that the results have not been tampered with. dsh-security-assurance is designed to address this trust-chain problem by providing policy-driven, evidence-based security assessment.
What Is This¶
dsh-security-assurance is a policy-driven repository security assessment plugin for DeepSeek Harness. It is maintained by bailong-Hakuryu, integrates through public Harness/Cordis interfaces, does not modify Harness Core, and encapsulates the assessment process into versioned results that are queryable, recoverable, and auditable.
This is a security assurance plugin, not a general-purpose vulnerability scanner. Current built-in capabilities include package.json install-lifecycle checks for Node projects, npm publish-surface checks, pnpm lockfile integrity checks, GitHub Actions permissions and immutable dependency checks, and pure normalization plus independent verification of frozen npm-audit.json and Gitleaks v8 JSON reports.
Core Features¶
The plugin mainly provides the following capabilities:
-
Assessment Modes and Subjects:
- Supports
REPOSITORY(repository),CHANGE(Mission output workspace), andTARGETEDmodes. - Supported subjects include
git_revision,workspace_snapshot, andchange.
- Supports
-
Specific Check Policies:
- Node Projects:
package.jsoninstall-lifecycle checks and npm publish-surface checks. - Dependency Management: pnpm lockfile integrity checks.
- CI/CD: GitHub Actions permissions and immutable dependency checks.
- Report Normalization: normalization and independent verification of frozen
npm-audit.jsonand Gitleaks v8 JSON reports.
- Node Projects:
-
Assessment Profiles:
- Current v0.1 Analyzer qualification only attests the
security/standardpath. - If a repository binds
security/deepor a host custom profile, Catalog explicitly reports that it is unsupported.
- Current v0.1 Analyzer qualification only attests the
Installation and Enablement¶
The plugin is installed from the catalog. Because the official documentation does not provide a direct command-line installation instruction, it is recommended to register it in the Harness environment through the catalog link.
The plugin requires a Node.js runtime, with the version requirement ^22.19.0 || >=24.0.0.
Typical Usage¶
- Select a Mode: Use
REPOSITORY,CHANGE, orTARGETEDmode for evaluation. - Specify a Subject: Specify the evaluation target using
git_revision,workspace_snapshot, orchange. - Configure a Policy: Use the default policy
security/node-package-lifecycle, or select policies such assecurity/npm-dependency-audit,security/secret-leak-audit,security/github-actions-supply-chain,security/npm-publish-surface, orsecurity/pnpm-lockfile-integrityas needed. - Process Release Files: Process release files using the
dsh-security-assurance-release-*CLI tool family.
Applicable Scenarios and Notes¶
- Positioning: It is primarily used for security assurance rather than general vulnerability scanning. A single scan finding is not equivalent to an auditable security conclusion, because inputs may be tampered with, truncated, or inconsistent with the frozen repository.
- Permissions and Qualification: Security Assurance only accepts verified slices on a frozen subject. All roles are
PROPOSAL_ONLY; they cannot approve, accept risk, or determine a Verdict. - Profile Limitation: Security Assurance only supports v0.1 Analyzer qualification for the
security/standardpath. - License: It uses the MIT License.
Conclusion¶
This plugin provides DeepSeek Harness with a closed-loop security assessment process from evidence collection to independent verification. If you need to implement auditable security policies in the plugin ecosystem, see its documentation and catalog page.