Foreword¶
In the DeepSeek Harness (DSH) ecosystem, Stacked PRs are commonly used to manage multi-level code changes with dependencies. However, when a base PR needs to be modified, rebasing operations rewrite commit SHAs, causing previous CI validation records to become invalid. Without additional checks, developers may mistakenly believe that “tests passed” and merge directly, thereby introducing unverified code.
dsh-stack is a Cordis plugin for DeepSeek Harness that provides a set of mandatory security policies for stacked PR workflows. It covers the entire process from synchronization and validation to merging and cleanup. Through SHA-bound validation records, it ensures that the test state before each merge is traceable and valid. This is a defense-in-depth supplement to GitHub branch protection rules, not a replacement.
Core Features¶
During command execution, dsh-stack validates the following eight security checkpoints in sequence:
-
G-ENV (Environment and Authentication Check)
Ensures the current environment meets the requirements: GitHub CLI version >= 2.90.0,gh-stackextension version >= 0.1.0, and GraphQL authentication permissions. -
G-TREE (Workspace Cleanliness Check)
Before performing synchronization or rebasing, checks the working tree usinggit status --porcelain. If uncommitted changes exist, the operation is blocked. -
G-TOPO (Topology Check)
Validates the integrity of PR dependency chains and rejects cross-fork repositories, circular dependencies, or isolated nodes. -
G-TEST (Rewritten Layer Testing Check)
When rebasing reaches a given layer, forces execution of that layer’s local test suite (defaultpnpm testornpm test) and writes test results to validation records. -
G-VERIFY (Validation Record Check)
Rejects merging a branch whose current Head SHA has no corresponding validation record. If the record is missing, expired, or failed, the merge request is blocked. -
G-LAND (Merge Eligibility Check)
Checks whether the CI build status is green and whether code review has been approved. -
G-POLL (Merge Status Polling)
After performing the merge, continuously polls the GitHub API to confirm that the branch status isMERGED. -
G-DEL (Zero-Dependency Cleanup Check)
Before deleting a branch, strictly checks whether the branch has open dependencies. Deletion is allowed only when the dependency count is 0.
Installation and Configuration¶
Installation¶
Install the plugin via npm:
dsh plugin --profile default add dsh-stack
Prerequisites¶
Before installing, ensure the environment meets the following requirements:
* Node.js >= 22
* GitHub CLI >= 2.90.0
* gh-stack extension >= 0.1.0
Configure the Test Command¶
By default, the plugin uses pnpm test or npm test. If the project uses another testing framework, the validation command must be specified in the configuration file. The configuration file path is $DSH_HOME/profiles/default/cordis.patch.yml:
- replace:
- id: stack
config:
validationCommand: ['pytest', '-q'] # 自定义测试命令,以数组形式传入
validationTimeoutMs: 600000 # 设置超时时间(毫秒)
Note: Changing
validationCommandinvalidates previous validation records, so the validation flow must be rerun.
Verify Installation¶
After installation, you can confirm that the configuration is effective with the following command:
dsh --profile default --dump-config | grep stack
Applicable Scenarios and Notes¶
Applicable scenarios:
* Developers using gh stack for multi-level PR management.
* Teams relying on CI results to determine merge approval.
* DSH users who want to add an additional layer of security at the local command-line level.
Notes:
* Defense in depth: This plugin is part of a defense strategy and should not replace GitHub repository branch protection rules.
* Build script restrictions: If using pnpm >= 10, build scripts for Git dependencies may be blocked. If installation fails, add the package name to the allowBuilds field in $DSH_HOME/profiles/default/pnpm-workspace.yaml.
* Record invalidation: Changing the validation command invalidates historical records, and tests must be rerun.