In the plugin ecosystem of DeepSeek Harness (DSH), verifying the integrity of software releases typically relies on external transparency logs or complex build pipelines. dsh-attestation-proof focuses on meeting this specific need: it provides offline, deterministic release attestations. Unlike dsh-release-proof, which requires downloading and comparing byte streams, this plugin directly validates consistency between the manifest and local subjects against pinned keys.
What Is This¶
This is a plugin maintained by dongsheng123132, designed to generate offline, deterministic evidence. It verifies whether the manifest matches the signed subjects and checks DSSE/in-toto statements. It pins Ed25519 or ECDSA public keys by SHA-256 and outputs deterministic, content-based JSON verdicts.
The plugin fills a specific gap in existing tools: it does not execute build commands, infer publisher identity, or rely on external transparency logs. It only handles validation relationships among the manifest, subjects, and pinned keys.
Core Features¶
- Offline Deterministic Release Proof: Verification can be completed without network access, ensuring reproducibility.
- Key and Subject Verification: Supports DSSE/in-toto statements and pins Ed25519 or ECDSA public keys by SHA-256.
- Secure Report Generation: Reports never contain signed payloads, subject bytes, public key PEMs, or any sensitive information.
- Strict Filesystem Constraints: All filesystem inputs and artifact directories must be located within an explicit workspace. Symbolic links, path traversal, oversized inputs, and lifecycle scripts are rejected.
Installation and Enablement¶
The plugin can be installed from the community catalog. In DSH environments, the plugin registers the dsh_attestation_proof_inspect and dsh_attestation_proof_verify commands.
Typical Usage¶
Using the plugin typically involves two steps: inspecting evidence and verifying evidence.
- Inspect Evidence
Use the inspect command to generate or inspect proof files:
dsh-attestation-proof inspect --workspace . --manifest proof.json
- Verify Evidence
Use the verify command to validate consistency among the manifest, subjects, and pinned keys:
dsh-attestation-proof verify --workspace . --manifest proof.json --artifactDir artifacts
The exit codes for the verify command are as follows:
* 0: Verification passed.
* 2: Key or policy rejection (for example, invalid signature or threshold not met).
* 1: Invalid or unsafe input (for example, path traversal attempt).
Standard output contains the verification result in JSON format, and error messages are written to standard error.
Use Cases and Notes¶
- Use Cases: Developers who need to verify release evidence in offline environments or perform supply chain security audits, and projects that need strict control over proof file contents.
- Notes:
- The plugin runs with the permissions of the current DSH process. Check the source code and license before installation.
- Verification is fully offline and does not depend on external services.
- Reports do not contain sensitive data; they include only content-based JSON verdicts.
Summary¶
dsh-attestation-proof provides DeepSeek Harness with a lightweight, offline supply chain security verification method. By using pinned keys and content addressing, it ensures the determinism and security of release attestations, making it suitable for scenarios with strict build-environment isolation requirements. View details in the community catalog or obtain the source code on GitHub.