DDS Plugin SDK 0.3.1 Developer Preview
Pre-releaseSDK 0.3.1 lets consumers verify a downloaded DDS plugin package before loading it.
verifyPluginArchive()anddds-plugin verifycheck the bounded gzip/ustar format, exact file allowlist, hashes, manifest, disclosures, license and generated npm metadata without extracting or executing plugin code.- Supply an independently obtained SHA-256 to pin the selected archive bytes. Links, unsafe or duplicate paths, unlisted files, npm hooks/dependencies, malformed archives and oversized inputs are rejected.
- Includes TypeScript declarations, English/Korean verification guidance and a complete installed-package example that packages, verifies and rejects a tampered download.
- Aligns the theme metadata's popover-radius default with current DDS (16). Omitted metrics remain omitted, and explicit example values remain unchanged. Hello Ocean's two palettes and 28 tokens per mode round-trip through the current DDS parser.
Install the versioned GitHub archive:
npm install --save-exact https://github.com/Altifigence/dds-plugin-sdk/releases/download/v0.3.1/altifigence-dds-plugin-sdk-0.3.1.tgzNode.js 22 or 24 is supported. This developer preview is distributed through GitHub Releases; it is not an npm registry publication. Runtime, manifest and workspace contracts and the >=0.3.0 <0.4.0 plugin peer range are preserved. Existing 0.3.0 plugin archives can be verified without repacking.
Validation: 125 runtime tests, nine schemas, TypeScript consumers, the exact 90-file published inventory and independently installed CLI/API examples pass on Windows and Ubuntu with Node 22 and 24.
The verifier supports archives produced by the 0.3.x DDS plugin packer. The paired metadata is unsigned; a matching hash alone does not authenticate a publisher, scan malware, grant execution permission or qualify a DDS installation. Receipts describe the bytes read during that call. SDK npm tarballs use the attached SHA256SUMS.txt, not dds-plugin verify.
Read Archive verification, Compatibility and Themes. SDK materials remain Apache-2.0; plugin publishers retain their own applicable terms.