v1.4.14 — catalog plugins that ship a GitHub release package now install
v1.4.14 — catalog plugins that ship a GitHub release package now install
DSH Plugin Hub is the community plugin marketplace for DeepSeek Harness. This release fixes the installation of catalog plugins distributed as a prebuilt GitHub release .tgz instead of an npm package: with no npm name the install target fell back to the repository root, which has no entry file, and the install failed with entry file missing index.js.
Website: dsh-plugin.org
What's New
-
Prebuilt GitHub release packages are now a first-class install channel — A catalog entry that names a release
.tgzand has no npm package used to be installed from the repository, which selected the monorepo root and failed withentry file missing index.js. Such entries are now installed from the package the author actually published (#93). -
Release targets are matched strictly — Only a fixed
https://github.com/<owner>/<repo>/releases/download/<tag>/<asset>.tgztarget is accepted, and only when its repository matches the catalog repository. Cross-repository redirects, foreign hosts, credentials, movinglatestURLs, query or fragment data, path traversal, and appended CLI arguments or shell code are rejected. -
The repository-HEAD preflight no longer blocks release packages — Prebuilt release packages do not share the repository's HEAD layout, so the entry check that reads the HEAD tarball is skipped for them; the post-install entry validation still applies.
-
Repository identity is preserved for release installs — Installed-state readback, deduplication and display still resolve a release target back to its
owner/repo.
Thanks to @loopx-agent for the report and the reference implementation in #93.
Installation
Option 1 · via npm (recommended):
dsh plugin --profile web add dsh-pluginOption 2 · via the official GitHub repository:
dsh plugin --profile web add git+https://github.com/dshplugin/dsh-plugin-hub.git