Introduction

The core idea of DeepSeek Harness (DSH) is “everything is a plugin.” In software license compliance management, developers typically need to complete scanning first (for example, using dsh-license-guard), then perform expert review, and finally prove that all required compliance artifacts (such as NOTICE files, license texts, source packages, and others) have been delivered for a particular release decision. The dsh-license-obligation-proof plugin is designed for this purpose. It focuses on generating and verifying delivery evidence, rather than performing scanning or legal interpretation.

What This Is

This is an evidence-generation DSH plugin.
* Positioning: Provides offline, deterministic evidence that all required compliance artifacts have been delivered for a particular release decision.
* Maintainer: dongsheng123132
* License: MIT

Core Features

The plugin does not perform scanning; instead, it focuses on verifying the delivery closure:
1. Evidence Generation: Generates offline evidence for compliance artifacts such as NOTICE files, license texts, source availability, and modification notices. Inputs and reports contain only hashes, obligation codes, and bounded metadata; they do not include license body, copyright text, package source code, or keys.
2. Consistency Validation: Validates that the declared component set, decision, obligations, delivered artifact hashes, independent receipts, and zero unresolved closure status are consistent.
3. Report Flags: Reports explicitly retain the provesComponentSetExhaustive: false and provesLegalCompliance: false flags.

Installation and Activation

The plugin is distributed through the DSH ecosystem.
* Installation: Install it via the DSH plugin catalog or the GitHub repository.
* Prerequisites: Ensure the DSH version satisfies >=0.1.2-alpha.4 and the Node.js version satisfies >=22.

Typical Usage

The plugin provides the following commands for testing, checking, and verification:

npm test

Runs unit tests.

npm run check

Runs script checks.

node bin/dsh-license-obligation-proof.mjs verify examples/closed.json

Verifies the sample file examples/closed.json and checks the delivery closure status.

Applicable Scenarios and Notes

  • Use cases: After code scanning and expert review are completed, it is used to prove the delivery status of compliance artifacts.
  • Important notes:
    • Not a scanner: This is not a license scanner. It does not scan node_modules, does not normalize SPDX, does not interpret licenses, and does not provide legal advice.
    • Permission scope: The plugin runs with the DSH process permissions; ensure the source code is trusted.
    • Report meaning: Reports generated by the plugin retain provesComponentSetExhaustive: false and provesLegalCompliance: false, which means it confirms the delivery process but does not guarantee that the component set is exhaustive or that legal compliance is satisfied.

Conclusion

This plugin fills the gap between “compliance scanning” and “compliance delivery proof.” For developers and compliance personnel who need to strictly audit the evidence behind release decisions, it provides deterministic evidence based on hashes and metadata.