Foreword

In the DeepSeek Harness (DSH) ecosystem, Stacked PRs are commonly used to manage multi-level code changes with dependencies. However, when a base PR needs to be modified, rebasing operations rewrite commit SHAs, causing previous CI validation records to become invalid. Without additional checks, developers may mistakenly believe that “tests passed” and merge directly, thereby introducing unverified code.

dsh-stack is a Cordis plugin for DeepSeek Harness that provides a set of mandatory security policies for stacked PR workflows. It covers the entire process from synchronization and validation to merging and cleanup. Through SHA-bound validation records, it ensures that the test state before each merge is traceable and valid. This is a defense-in-depth supplement to GitHub branch protection rules, not a replacement.

Core Features

During command execution, dsh-stack validates the following eight security checkpoints in sequence:

  1. G-ENV (Environment and Authentication Check)
    Ensures the current environment meets the requirements: GitHub CLI version >= 2.90.0, gh-stack extension version >= 0.1.0, and GraphQL authentication permissions.

  2. G-TREE (Workspace Cleanliness Check)
    Before performing synchronization or rebasing, checks the working tree using git status --porcelain. If uncommitted changes exist, the operation is blocked.

  3. G-TOPO (Topology Check)
    Validates the integrity of PR dependency chains and rejects cross-fork repositories, circular dependencies, or isolated nodes.

  4. G-TEST (Rewritten Layer Testing Check)
    When rebasing reaches a given layer, forces execution of that layer’s local test suite (default pnpm test or npm test) and writes test results to validation records.

  5. G-VERIFY (Validation Record Check)
    Rejects merging a branch whose current Head SHA has no corresponding validation record. If the record is missing, expired, or failed, the merge request is blocked.

  6. G-LAND (Merge Eligibility Check)
    Checks whether the CI build status is green and whether code review has been approved.

  7. G-POLL (Merge Status Polling)
    After performing the merge, continuously polls the GitHub API to confirm that the branch status is MERGED.

  8. G-DEL (Zero-Dependency Cleanup Check)
    Before deleting a branch, strictly checks whether the branch has open dependencies. Deletion is allowed only when the dependency count is 0.

Installation and Configuration

Installation

Install the plugin via npm:

dsh plugin --profile default add dsh-stack

Prerequisites

Before installing, ensure the environment meets the following requirements:
* Node.js >= 22
* GitHub CLI >= 2.90.0
* gh-stack extension >= 0.1.0

Configure the Test Command

By default, the plugin uses pnpm test or npm test. If the project uses another testing framework, the validation command must be specified in the configuration file. The configuration file path is $DSH_HOME/profiles/default/cordis.patch.yml:

- replace:
    - id: stack
      config:
        validationCommand: ['pytest', '-q']     # 自定义测试命令,以数组形式传入
        validationTimeoutMs: 600000             # 设置超时时间(毫秒)

Note: Changing validationCommand invalidates previous validation records, so the validation flow must be rerun.

Verify Installation

After installation, you can confirm that the configuration is effective with the following command:

dsh --profile default --dump-config | grep stack

Applicable Scenarios and Notes

Applicable scenarios:
* Developers using gh stack for multi-level PR management.
* Teams relying on CI results to determine merge approval.
* DSH users who want to add an additional layer of security at the local command-line level.

Notes:
* Defense in depth: This plugin is part of a defense strategy and should not replace GitHub repository branch protection rules.
* Build script restrictions: If using pnpm >= 10, build scripts for Git dependencies may be blocked. If installation fails, add the package name to the allowBuilds field in $DSH_HOME/profiles/default/pnpm-workspace.yaml.
* Record invalidation: Changing the validation command invalidates historical records, and tests must be rerun.