Preface¶
In the supply chain management of DeepSeek Harness (DSH), verifying whether an immutable artifact strictly follows the declared build, staging, and production promotion chain is a key step to ensuring environment consistency. Traditional verification methods often require deployment, registry invocations, or runtime health checks, which not only take time but may also introduce unnecessary side effects. dsh-artifact-promotion-proof focuses on providing an offline, deterministic evidence layer. It does not rely on network requests or external services, and completes promotion-chain compliance checks solely through hash records.
Plugin Introduction¶
dsh-artifact-promotion-proof is a security governance plugin maintained by dongsheng123132. Its core responsibility is to generate offline, content-addressed proofs that verify whether a specific artifact hash maintains continuity in the declared promotion chain.
It solves the problem of: without any deployment operations, registry calls, or runtime health checks, verifying solely from provided hash records whether an artifact has passed each stage completely, in order, and in policy compliance. It is not responsible for certifying receipts or validating origin signatures; it only verifies the internal integrity of the data structures.
Core Features¶
The plugin provides a strict but non-intrusive verification mechanism:
- Promotion chain verification: Checks whether artifact hashes are strictly continuous in the declared build → staging → production chain.
- Environment binding checks: Ensures that evidence for each stage includes precise environment bindings, prerequisite receipts, and gate evidence.
- Zero-rebuild promotion: Supports zero-rebuild promotion continuity across declared deployment stages.
- Deterministic evidence: Generates a deterministic, content-addressed evidence layer for DeepSeek Harness supply chain auditing.
- Report structure: Verification reports only include hash values, counts, booleans, gate classifications, and final verdicts, and do not contain raw logs, subjects, or content fields.
Installation and Activation¶
Installing this plugin requires using the DSH profile mechanism. Ensure your DeepSeek Harness version meets compatibility requirements (>= 0.1.2-alpha.4).
Run the following command to install:
dsh plugin --profile evidence add github:dongsheng123132/dsh-artifact-promotion-proof#COMMIT
After installation, the plugin exposes related CLI and MCP interfaces.
Typical Usage¶
The plugin provides two usage methods: CLI and MCP stdio. The core commands both include inspect and verify operations.
CLI Usage:
dsh_artifact_promotion_inspect
dsh_artifact_promotion_verify
The CLI accepts an inspect or verify operation and supports explicitly specifying a JSON path.
MCP stdio Usage:
The MCP server exposes the following interfaces:
- artifact_promotion_inspect
- artifact_promotion_verify
Verification Tool Requirements:
The DSH verify tool needs to read a workspace-relative, non-symlink manifest and write output to the specified workspace-relative path artifactDir. The verification process ensures content determinism by reading back the output.
Node.js 22 or later is a prerequisite for running this plugin.
Use Cases and Notes¶
This plugin is suitable for scenarios that require static auditing of supply-chain promotion flow, such as security compliance checks and automated audit pipelines.
When using it, note the following:
- Permissions and side effects: The plugin runs with the current DSH process permissions and will not perform deployment, invoke registries, grant approvals, validate runtime health, or modify the environment.
- Verification scope: The verifier’s “promoted” verdict only means that the provided hash records are internally complete, ordered, and policy-compliant. It does not mean that it certifies receipts or validates origin signatures.
- Data format restrictions: The plugin rejects secret-like material and raw log/subject/content fields, and only processes structured hash records.
- Runtime characteristics: The verifier itself has no runtime dependencies, does not generate processes, and does not initiate any network requests.
- Stage order: Each stage in the manifest must appear exactly once and must be ordered correctly; otherwise, verification will fail.
Brief Conclusion¶
dsh-artifact-promotion-proof provides DeepSeek Harness with a low-level, deterministic evidence layer. By removing the complexity of deployment and health checks, it allows developers to focus on the completeness and ordering of data records. For scenarios focused on static supply-chain compliance, it is a reliable tool. For more details, refer to the plugin directory or the GitHub repository.