Introduction

DeepSeek Harness allows capabilities to be extended through plugins. In repository security, common static scanning tools often only produce results, making it difficult to trace their origin or prove that the results have not been tampered with. dsh-security-assurance is designed to address this trust-chain problem by providing policy-driven, evidence-based security assessment.

What Is This

dsh-security-assurance is a policy-driven repository security assessment plugin for DeepSeek Harness. It is maintained by bailong-Hakuryu, integrates through public Harness/Cordis interfaces, does not modify Harness Core, and encapsulates the assessment process into versioned results that are queryable, recoverable, and auditable.

This is a security assurance plugin, not a general-purpose vulnerability scanner. Current built-in capabilities include package.json install-lifecycle checks for Node projects, npm publish-surface checks, pnpm lockfile integrity checks, GitHub Actions permissions and immutable dependency checks, and pure normalization plus independent verification of frozen npm-audit.json and Gitleaks v8 JSON reports.

Core Features

The plugin mainly provides the following capabilities:

  1. Assessment Modes and Subjects:

    • Supports REPOSITORY (repository), CHANGE (Mission output workspace), and TARGETED modes.
    • Supported subjects include git_revision, workspace_snapshot, and change.
  2. Specific Check Policies:

    • Node Projects: package.json install-lifecycle checks and npm publish-surface checks.
    • Dependency Management: pnpm lockfile integrity checks.
    • CI/CD: GitHub Actions permissions and immutable dependency checks.
    • Report Normalization: normalization and independent verification of frozen npm-audit.json and Gitleaks v8 JSON reports.
  3. Assessment Profiles:

    • Current v0.1 Analyzer qualification only attests the security/standard path.
    • If a repository binds security/deep or a host custom profile, Catalog explicitly reports that it is unsupported.

Installation and Enablement

The plugin is installed from the catalog. Because the official documentation does not provide a direct command-line installation instruction, it is recommended to register it in the Harness environment through the catalog link.

The plugin requires a Node.js runtime, with the version requirement ^22.19.0 || >=24.0.0.

Typical Usage

  1. Select a Mode: Use REPOSITORY, CHANGE, or TARGETED mode for evaluation.
  2. Specify a Subject: Specify the evaluation target using git_revision, workspace_snapshot, or change.
  3. Configure a Policy: Use the default policy security/node-package-lifecycle, or select policies such as security/npm-dependency-audit, security/secret-leak-audit, security/github-actions-supply-chain, security/npm-publish-surface, or security/pnpm-lockfile-integrity as needed.
  4. Process Release Files: Process release files using the dsh-security-assurance-release-* CLI tool family.

Applicable Scenarios and Notes

  • Positioning: It is primarily used for security assurance rather than general vulnerability scanning. A single scan finding is not equivalent to an auditable security conclusion, because inputs may be tampered with, truncated, or inconsistent with the frozen repository.
  • Permissions and Qualification: Security Assurance only accepts verified slices on a frozen subject. All roles are PROPOSAL_ONLY; they cannot approve, accept risk, or determine a Verdict.
  • Profile Limitation: Security Assurance only supports v0.1 Analyzer qualification for the security/standard path.
  • License: It uses the MIT License.

Conclusion

This plugin provides DeepSeek Harness with a closed-loop security assessment process from evidence collection to independent verification. If you need to implement auditable security policies in the plugin ecosystem, see its documentation and catalog page.