Introduction

DeepSeek Harness (DSH) uses a plugin-based architecture and extends functionality through extension packages. In the Web UI, managing dependencies in the current profile (including npm packages, Git repositories, and local links) usually requires manually operating command-line tools. The plugin introduced below adds a “Plugin Packages” page to Settings, providing a graphical dependency management interface.

What It Is

This is a community plugin maintained by hyqhyq3 (MIT license). It adds a “Settings → Plugin Packages” page to the DSH Web UI, lists every dependency installed in the current profile, shows its version and source, and supports one-click install, update, and removal. The plugin itself does not provide a model interaction interface; it only serves the Settings page and backend APIs.

Installation and Activation

Installing the plugin requires using DSH’s package manager commands.

dsh plugin --profile web add github:hyqhyq3/dsh-plugin-updater

After installation, DSH must be restarted for the change to take effect. After the restart, open “Settings” → “Plugin Packages” in the Web UI to see the new page.

Core Features

1. Dependency Manifest and Status

The page lists all packages in dependencies for the current profile and shows their:
* Installed version
* Source (npm / Git / local / built-in)
* Whether they are in the currently active bundle layer (dsh.profile.bundles)

2. Update Detection

The plugin implements automatic detection logic for different sources:
* npm: Compares the installed version with the latest dist-tags returned by pnpm view.
* Git: Compares the commit recorded in the local lockfile with the latest tag in the remote repository.
* Local: Compares local HEAD with origin HEAD and detects whether a fetch is needed.
* Built-in: Shows the version and updates together with DSH installations.

3. Plugin Marketplace

In the “Store” tab, users can search GitHub repositories tagged with the dsh-plugin topic. Search results can be sorted by relevance, star count, or last update time, and support pagination. During installation, the repository is directly added as a github:owner/repo dependency.

4. Build Script Gating

To address the security restrictions in pnpm >= 10, the plugin refuses installation when an install script is not on the allowlist. In that case, the page provides an “Allow build scripts and retry” button, automatically writes the suggested allowBuilds configuration into pnpm-workspace.yaml, and re-runs the installation.

Typical Usage

Search and install:
1. Switch to the “Store” tab.
2. Enter a keyword to search.
3. Click “Install” for the target repository.

Handle updates:
1. Switch to the “Installed” tab.
2. Locate a package with an update and click “Update”.
3. If blocked by build scripts, click “Allow build scripts and retry”.

Remove:
Click the “Remove” button next to the package. After confirmation, the plugin runs pnpm remove and rebalances the bundle layers.

Notes

  • Requires restart: Changes to the profile configuration (install, update, remove) do not take effect immediately. The DSH process must be restarted, and the page displays a restart notification banner.
  • Self-protection: This plugin page cannot unload itself through the “Remove” button. Use the command line instead: dsh plugin --profile <name> remove dsh-plugin-updater.
  • Marketplace limits: If no token is provided, the GitHub search API is limited to 10 requests per minute. Results are cached for about 5 minutes to mitigate the limit.
  • Management scope: The plugin only manages dependencies in the profile manifest. It does not enable or disable runtime loader entries.
  • Local dependencies: Update checks are performed only when the install source is link: or includes a .git target.
  • Git update logic: Update detection for Git packages is based on the ref specified in the spec. Moving tags are not automatically treated as updates.

Technical Details

The plugin is written in pure ESM JavaScript and has no external dependencies. The server side runs inside the DSH process, discovers the current profile through lib/index.js, and invokes pnpm commands. The client side registers the Settings page through lib/client.js and polls status. It provides a complete HTTP API under /plugin-updater/api/*, including status queries, GitHub search, and operation interfaces for installing, updating, and removing packages.

Summary

This plugin solves the inconvenience of dependency management in the DSH Web UI by providing a graphical interface for uniform management of npm, Git, and local packages. For developers who need to frequently maintain DSH profiles, it can significantly improve efficiency.

Plugin directory page | GitHub repository