Airmetro/dsh-update-checker

Update management for the whole stack: compares DeepSeek Harness and every installed third-party plugin against npm and GitHub releases (semver-aware), shows a locale-aware banner (zh/en) with per-plugin update status, and provides one-click updates with automatic backup/rollback, temp-dir installs that never touch other packages, and a watchdog-guarded restart. A settings page adds per-plugin version lamps, live update progress, and banner/notification toggles. Zero-config on any machine.

dsh-update-checker is a permanent Cordis plugin for DeepSeek Harness Web that auto-checks for new DSH releases and third-party plugin updates, asks the user, and provides one-click updates with success/failure feedback and rollback. Features: Full update lifecycle — check, backup, update, rollback, and restart, all in one plugin. Main program check compares the installed @deepseek-ai/dsh against npm latest (semver-aware, stable-first, pre-release tags don't cause false positives). Third-party plugin check scans all non-official installed plugins and cross-compares each against npm + GitHub; local tools with no publish source go to 'ignored'. Dedicated HTTPS client for GitHub (tolerates self-signed proxies; npm still uses strict TLS), with redirects, size caps, and timeouts — codeload tarballs validated before install. In-GUI banner shows locale-aware update / up-to-date / failure state with change brief (vX→vY + risk level + release notes when available). One-click update with safety: dry-run guard (abort if plan contains 'remove') → backup → layout-adaptive install → post-install verification. Real rollback capability. Updates persist to profile package.json + lockfile so a later install never silently reverts the plugin.

Development & Runtime ★ 8 updated 2026-08-22
View on GitHub ↗

Install

npm i dsh-update-checker --prefix <temp-dir> --no-save && cp -r <temp-dir>/node_modules/dsh-update-checker $DSH_HOME/profiles/node_modules/

npm package dsh-update-checker 1.4.15 (registry-verified 2026-08-23). Install per official README: (1) Create a temp dir and install the package without running npm install inside $DSH_HOME/profiles (which would prune node_modules): npm i dsh-update-checker --prefix <temp-dir> --no-save; then cp -r <temp-dir>/node_modules/dsh-update-checker $DSH_HOME/profiles/node_modules/. Alternative: copy the package directory from a git clone or tarball. (2) Add the plugin row to $DSH_HOME/profiles/web/cordis.patch.yml. Note: the package declares dsh.bundle.patch; modern DSH 0.1.0-rc.8+ may also support dsh plugin --profile web add dsh-update-checker directly. The README's manual steps apply when the dsh plugin command is not available.

Compatibility

DeepSeek Harness web profile. Permanent Cordis plugin. Checks both the main @deepseek-ai/dsh npm package (stable-first, semver-aware, pre-release latest tag doesn't cause false positives) and all installed non-official (third-party) plugins via npm + GitHub cross-compare. Working GitHub channel with dedicated HTTPS client (tolerates self-signed local proxies; npm registry uses strict TLS), redirects, size caps, and timeouts. In-GUI banner is locale-aware (zh/en follows the DSH UI language). Updates and rollbacks persist to the profile package.json + lockfile so a later install never silently reverts a plugin.

Details

Recent updates

The current English README (README.md, primary English) documents: full update lifecycle (check/backup/update/rollback/restart), main program check (semver-aware, stable-first), third-party plugin check (npm + GitHub cross-compare, layout-agnostic), GitHub HTTPS client, in-GUI locale-aware banner, one-click update with dry-run guard and post-install check, real rollback, lockfile-persisted updates, and the manual install procedure (npm prefix + copy to profiles/node_modules + cordis.patch.yml).

FAQ

Why does the README show a manual npm + copy install instead of dsh plugin add?
The README was written before the dsh plugin command was standardized. The plugin declares dsh.bundle.patch so modern DSH 0.1.0-rc.8+ may support dsh plugin --profile web add dsh-update-checker directly. If that fails, follow the manual steps in the README (npm install to a temp dir, copy to $DSH_HOME/profiles/node_modules, add to cordis.patch.yml).
Does it check for updates to third-party plugins, not just DSH itself?
Yes — it scans all installed non-official plugins and cross-compares each against npm + GitHub. Plugins with no publish source (local-only tools) are classified as 'ignored'. Only official @deepseek-ai/* packages are excluded from the third-party scan.
Will updating a plugin silently revert after a future install?
No — updates persist to the profile package.json + lockfile (pnpm install --lockfile-only / npm install --package-lock-only) so a later install or dsh web restart cannot silently revert the plugin.

Alternatives

chenw2759-wq/dsh-plugin-healthcheck · omdsh-dev/dsh-security-audit · omdsh-dev/dsh-session-health

More plugins in Development & Runtime

Browse more in Development & Runtime

Guides for Development & Runtime plugins