Introduction

In the DeepSeek Harness (DSH) ecosystem, the default update behavior tends to be “floating”. For example, using dsh plugin --profile web update effectively runs pnpm update, which updates dependencies to their latest versions. Most existing community updaters (such as dsh-update-checker, dsh-safe-updater, etc.) also point profiles to the latest versions.

This default behavior can be risky when DSH is in the RC stage, or when plugins run in environments with process privileges. The problem that dsh-lockstep solves is: “Keep N machines on the same audited pin while noticing that the world has changed.”

What This Is

dsh-lockstep is a pin-based update tool in the DSH plugin ecosystem. It is maintained by da-beda. Its core logic is to compare the audited lockfile with the status on the npm registry and GitHub, plan pin bumps, and then stop. It does not “float” any dependency to the latest version.

Core Features

The plugin provides the following core capabilities:

  • Check lockfile drift: compare the currently locked versions with the latest state in the remote sources (npm or GitHub).
  • Plan pin bumps: when updates exist, generate a concrete bump plan.
  • Never float: strictly enforce the locking policy and do not automatically update to the latest version.

Installation and Enabling

You can install the plugin in two ways.

As a CLI tool (without DSH):

npx -y github:da-beda/dsh-lockstep#v0.1.1 check --lock plugins.lock.json

As a DSH plugin (registers lockstep_check / lockstep_plan tools):

dsh plugin --profile tui add github:da-beda/dsh-lockstep#v0.1.1
dsh plugin --profile web add github:da-beda/dsh-lockstep#v0.1.1

Typical Usage

The standard workflow for using dsh-lockstep is to check first, then plan, and finally apply changes.

  1. Check status
    dsh-lockstep check
    # 或者指定 lockfile
    dsh-lockstep check --lock plugins.lock.json
  1. View the change plan
    dsh-lockstep plan
  1. Apply changes and write
    The --write parameter must be passed explicitly. The apply command refuses to perform write operations when --write is not passed.
    dsh-lockstep apply --write

The complete operation chain is:
check → plan → review → apply --write → commit → run install.sh on each machine.

Applicable Scenarios and Notes

  • Applicable scenarios: environments that require strict control of dependency version consistency across multiple machines, especially when DSH is in an RC release or plugins involve system permissions.
  • Security mechanisms:
    • The plugin only communicates with the npm registry and GitHub and does not execute package install scripts.
    • Writing the lockfile is not equivalent to installing code; it is only an update to a configuration file.
  • Error handling:
    • The apply command refuses to write when --write is not used.
    • If GitHub API rate limits are encountered, set the environment variable GITHUB_TOKEN or GH_TOKEN.
  • Ecosystem background: The core philosophy of DSH is “everything is a plugin”. The community catalog is an independent site and has no official affiliation with DeepSeek / High-Flyer.
  • Plugin catalog: https://www.skillhub.cn/plugins/da-beda/dsh-lockstep
  • Source code: https://github.com/da-beda/dsh-lockstep