In the DeepSeek Harness (DSH) ecosystem, verifying the consistency of build processes is a common requirement. How can independent builders confirm that their outputs are identical? Existing tools usually check signatures or download status, but do not verify byte-level matching between independent builders. The dsh-reproducible-build-proof plugin is designed to address this problem.
What Is It¶
This is a DeepSeek Harness plugin that provides offline content-addressed proof to verify whether independent builds produce byte-for-byte identical outputs. It is maintained by dongsheng123132.
It focuses on validating the convergence of independent builds: confirming whether multiple independent operators, using the same source revision, recipe, build type, parameters, dependency set, and associated environment contracts, ultimately produce the same designated artifact byte-for-byte.
Core Features¶
- Offline content-addressed proof: Validates outputs without network requests.
- Independent build convergence validation: Checks the consistency of input declarations.
- Input checks: Verifies source revision, recipe, build type, parameters, dependency set, and environment contracts.
- Explicit hash receipts: Only validates explicit hashes; does not execute builds or packages.
- Deterministic output: Generates deterministic content-addressed outputs.
- No runtime dependencies: The validator itself has no external dependencies.
Installation and Enablement¶
Run the following command in the terminal to install the plugin:
dsh plugin add github:dongsheng123132/dsh-reproducible-build-proof#COMMIT
Typical Usage¶
The plugin provides multiple invocation methods.
- CLI commands: You can directly use the
dsh_reproducible_build_inspectanddsh_reproducible_build_verifycommands. - MCP stdio server: Exposes the
reproducible_build_inspectandreproducible_build_verifyinterfaces through an MCP stdio server. - CLI JSON path: The CLI supports argument forms that use inspect or verify together with an explicit JSON path.
At runtime, the plugin reads workspace-relative non-symlink manifests and writes results into an explicit workspace-relative artifactDir. It rejects materials shaped like secrets, raw logs, and body/content fields.
Use Cases and Notes¶
- Functional boundaries: This plugin does not execute builds, packages, authenticate origins, issue SLSA Verified Property, or claim to protect against threats to source code, dependencies, or distribution. It only verifies the matching of explicit hash receipts. If origin attestation is required, use a provenance/signature verifier.
- Environment requirements: Requires Node.js 22 or newer.
- Network and dependencies: The validator has no runtime dependencies and does not initiate network requests.
- Manifest format: The DSH verify tool only reads workspace-relative non-symlink manifests.
Summary¶
This tool provides an offline, deterministic evidence layer for the DeepSeek Harness supply chain to validate the consistency of independent builds. To learn more details or view examples, you can access the plugin directory or the GitHub repository.