[Unofficial] [Plugin] dsh-pack — Portable, signed and verifiable DSH Agent Artifacts with OCI-distributed Evidence #5081
Replies: 4 comments 2 replies
把 artifact identity 和 trust policy 绑定起来这里列出的区分很重要:configHash、contentHash、lock、cache、registry 和 OCI digest 解决的不是同一个问题。要让 Agent artifact 可复现和可治理,发布物必须绑定到可验证的内容身份,而不能只依赖 registry tag 或当前 profile 配置。 建议在进入可安装/可运行状态前固定这些证据: 我整理了两份独立社区手册,分别覆盖插件打包/安装的可复现边界与供应链审计:First plugin lab 和 Community Plugin Audit。它们不是官方 DeepSeek 信任根,也不代表对 dsh-pack 的认证或背书;最终应以精确 artifact、签名策略和实际运行矩阵为准。 |
|
提示:本帖介绍的项目或社群并非 DeepSeek 或 DeepSeek Harness 官方运营,请大家自行甄别信息与链接,并注意账号、隐私和资产安全。 如需在本社区发布第三方项目介绍,请在标题或正文开头显著注明“非官方 / Unofficial”,并避免使用可能让人误认为官方的表述。 |
Update — v0.6.0 releasedA fairly large update since the original post.
The two major milestones since this discussion was opened are: v0.5 — Verifiable Agent ArtifactAdded:
v0.6 — Distributed Verifiable EvidenceAdded:
One principle I tried hard to preserve through the design is:
Remote Evidence may be discovered, downloaded and cryptographically valid, Release: I'd especially appreciate feedback on whether the Artifact / Evidence split |
Update — v0.6.1 released
v0.5 — Verifiable Agent ArtifactAdded:
v0.6 — Distributed Verifiable EvidenceAdded:
The main design principle remains:
Remote Evidence can be discovered and transported through OCI registries, v0.6.1 — Latest DSH compatibility fixv0.6.1 is a compatibility patch for current DSH 0.1.x prerelease lines. It fixes npm semver prerelease matching for
Current release: https://github.com/WHY-Daydream/dsh-pack/releases/tag/v0.6.1 npm: https://www.npmjs.com/package/@why-daydream/dsh-pack I'd still be very interested in feedback on:
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Important
Unofficial / Community Project
dsh-packis an independently developed and maintained third-party project.It is not an official DeepSeek or DeepSeek Harness project, and is not
affiliated with or endorsed by DeepSeek.
Please review the project information, source code, trust model and
installation instructions independently before use.
dsh-pack
dsh-packis a community plugin for building portable, reproducible andverifiable DSH Agent Artifacts, with OCI-based image and Evidence distribution.
It started as a small experiment around reproducible DSH Profile snapshots,
but gradually evolved into an application-level Agent Artifact / supply-chain
layer for DSH.
The current release is:
v0.6.1 — Latest DSH compatibility fix
What problem does it solve?
DSH Profiles are naturally composable and editable on a local machine.
But once an Agent/Profile needs to move between developers, CI, servers or
registries, several questions appear:
file:/link:dependencies?dsh-packtries to make these boundaries explicit.Evolution
All reactions