Introduction¶
The core idea of DeepSeek Harness (DSH) is “everything is a plugin.” In software license compliance management, developers typically need to complete scanning first (for example, using dsh-license-guard), then perform expert review, and finally prove that all required compliance artifacts (such as NOTICE files, license texts, source packages, and others) have been delivered for a particular release decision. The dsh-license-obligation-proof plugin is designed for this purpose. It focuses on generating and verifying delivery evidence, rather than performing scanning or legal interpretation.
What This Is¶
This is an evidence-generation DSH plugin.
* Positioning: Provides offline, deterministic evidence that all required compliance artifacts have been delivered for a particular release decision.
* Maintainer: dongsheng123132
* License: MIT
Core Features¶
The plugin does not perform scanning; instead, it focuses on verifying the delivery closure:
1. Evidence Generation: Generates offline evidence for compliance artifacts such as NOTICE files, license texts, source availability, and modification notices. Inputs and reports contain only hashes, obligation codes, and bounded metadata; they do not include license body, copyright text, package source code, or keys.
2. Consistency Validation: Validates that the declared component set, decision, obligations, delivered artifact hashes, independent receipts, and zero unresolved closure status are consistent.
3. Report Flags: Reports explicitly retain the provesComponentSetExhaustive: false and provesLegalCompliance: false flags.
Installation and Activation¶
The plugin is distributed through the DSH ecosystem.
* Installation: Install it via the DSH plugin catalog or the GitHub repository.
* Prerequisites: Ensure the DSH version satisfies >=0.1.2-alpha.4 and the Node.js version satisfies >=22.
Typical Usage¶
The plugin provides the following commands for testing, checking, and verification:
npm test
Runs unit tests.
npm run check
Runs script checks.
node bin/dsh-license-obligation-proof.mjs verify examples/closed.json
Verifies the sample file examples/closed.json and checks the delivery closure status.
Applicable Scenarios and Notes¶
- Use cases: After code scanning and expert review are completed, it is used to prove the delivery status of compliance artifacts.
- Important notes:
- Not a scanner: This is not a license scanner. It does not scan
node_modules, does not normalize SPDX, does not interpret licenses, and does not provide legal advice. - Permission scope: The plugin runs with the DSH process permissions; ensure the source code is trusted.
- Report meaning: Reports generated by the plugin retain
provesComponentSetExhaustive: falseandprovesLegalCompliance: false, which means it confirms the delivery process but does not guarantee that the component set is exhaustive or that legal compliance is satisfied.
- Not a scanner: This is not a license scanner. It does not scan
Conclusion¶
This plugin fills the gap between “compliance scanning” and “compliance delivery proof.” For developers and compliance personnel who need to strictly audit the evidence behind release decisions, it provides deterministic evidence based on hashes and metadata.
- Catalog page: dsh-license-obligation-proof
- Source code: GitHub