Skip to content
dsh.fish
Bundle

dsh-release-proof

Reproducible multi-source release evidence for DeepSeek Harness

Source
dongsheng123132
stars
3 stars
License
MIT
Updated
Updated 7 hours ago

Readme

# dsh-release-proof

[![CI](https://github.com/dongsheng123132/dsh-release-proof/actions/workflows/check.yml/badge.svg)](https://github.com/dongsheng123132/dsh-release-proof/actions/workflows/check.yml)
[![MIT license](https://img.shields.io/github/license/dongsheng123132/dsh-release-proof)](LICENSE)
[![Node.js 22+](https://img.shields.io/badge/Node.js-%E2%89%A522-339933?logo=nodedotjs&logoColor=white)](package.json)
[![Awesome DSH Plugins](https://img.shields.io/badge/Awesome_DSH-verified_lab-0969da)](https://github.com/dongsheng123132/awesome-dsh-plugins#2origin-plugin-lab)

Reproducible multi-source release evidence for [DeepSeek Harness](https://github.com/deepseek-ai/DeepSeek-Harness).

`dsh-release-proof` downloads every mirror declared in an explicit release manifest, verifies HTTP status, advertised and actual byte length, SHA-256, and release version, then writes a content-addressed JSON evidence file. It is aimed at the gap between “CI passed” and “users are receiving the same release from every download endpoint.”

Version 0.2.0 is a formal Codex plugin and standalone MCP server, and uses the namespace export shape required by the stock DSH Web Loader. A real Cordis boot regression test guards that loader contract.

This tool proves transport and mirror consistency against values supplied by the manifest. It does **not** prove publisher identity or verify signed release attestations; use a signature/provenance verifier alongside it when that is part of your threat model.

## Safety model

- Anonymous HTTP(S) only: source credentials, custom headers, cookies, query strings, and URL fragments are rejected.
- Every request has a manifest-bounded timeout, redirect count, and maximum response size.
- A worker pool caps total concurrent source checks (1–16).
- The manifest must declare the expected version, bytes, and SHA-256; each artifact needs at least two sources.
- The only write target is the explicit, workspace-relative `artifactDir`. Traversal and symlink escape are rejected.
- Evidence is content addressed, written exclusively, read back, and SHA-256 verified.
- Evidence contains no timestamps or latency measurements, so identical observations produce byte-identical JSON.

## Install in DSH

```bash
dsh plugin --profile web add github:dongsheng123132/dsh-release-proof
```

The package exposes a standard DSH bundle through `package.json#dsh.bundle.patch` and registers:

- `dsh_release_proof_inspect` — safely summarize a manifest without returning URLs.
- `dsh_release_proof_verify` — verify all sources and write a proof artifact.

Typical tool arguments:

```json
{
  "manifestPath": "release/release-manifest.json",
  "artifactDir": "release/evidence"
}
```

## MCP

The plugin also exposes a standalone stdio MCP server through `.mcp.json`:

- `release_manifest_inspect`
- `release_verify`

MCP accepts an explicit inline `manifestJson` of at most 1 MiB. It does not read or write the filesystem. Verification still uses anonymous HTTP(S), the manifest's timeout/concurrency/redirect/byte limits, and returns a deterministic content-address descriptor that can be recomputed by the caller.

## CLI

```bash
dsh-release-proof inspect \
  --root /path/to/workspace \
  --manifest release/release-manifest.json

dsh-release-proof verify \
  --root /path/to/workspace \
  --manifest release/release-manifest.json \
  --artifact-dir release/evidence
```

Exit code `0` means every check passed, `2` means a valid proof was written but the release failed verification, and `1` means an operational or manifest error.

## Manifest

See [`examples/release-manifest.example.json`](examples/release-manifest.example.json). A source can obtain the version from an artifact response header:

```json
{ "kind": "header", "name": "x-release-version" }
```

or an anonymous JSON sidecar:

```json
{ "kind": "json", "url": "https://downloads.example.com/version.json", "field": "release.version" }
```

`field` is a dot-separated object path. Redirect targets receive the same anonymous-URL validation before they are requested.

## Develop

```bash
npm test
npm run check
npm run smoke:plugin
npm run smoke:mcp
python C:/Users/ZhuanZ/.codex/skills/.system/plugin-creator/scripts/validate_plugin.py .
```

Requires Node.js 22 or newer. The package has no install lifecycle scripts and no runtime dependencies beyond the optional DSH tool SDK peer.

## License

MIT

Install

dsh plugin --profile web add github:dongsheng123132/dsh-release-proof

Profile: web

  • This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.
Source