dsh-verify-gate
其他 活跃维护

dsh-verify-gate

blueWhalei/dsh-verify-gate

轻量级工作流结案前置校验工具,自动拦截未通过工作区验证命令的结案请求,无需人工核验即可确保结案前提件合规,可无缝集成到现有工作流体系。

0
Stars 标星
0
Forks 分支
0
Watchers 关注
0
Open Issues
TypeScript
主要语言
MIT
开源协议
90 KB
仓库大小
1 个月前
最后推送
一键安装扩展 / 插件指令
dsh plugin --profile web add github:blueWhalei/dsh-verify-gate
git clone https://github.com/blueWhalei/dsh-verify-gate.git
git clone git@github.com:blueWhalei/dsh-verify-gate.git
README.md main

dsh-verify-gate

English | 中文

An open-source DeepSeek Harness plugin that requires the agent to run the workspace’s verification commands before it can conclude that work is done.

Pass/fail is decided only by process exit codes. A successful run writes an auditable receipt. After that, any successful mutating tool (for example edit, write, or bash) invalidates the receipt, so verification must pass again before conclude.

Install

Local path:

dsh plugin --profile web add /absolute/path/to/verify-gate

Or from GitHub (the repo includes the built lib/ entry points):

dsh plugin --profile web add github:blueWhalei/dsh-verify-gate

Restart Web, open the target workspace, then:

  1. Run /verify run, or have the model call verify_run
  2. Call verify_conclude only after every command exits 0

How commands are chosen

Resolution order:

  1. Non-empty config.commands always wins
  2. Otherwise auto-detect (on by default) requires exactly one common workspace marker:
    • package.json with scripts.test → pick the package manager from the lockfile / packageManager, then run <pm> test
    • go.mod → go test ./...
    • Cargo.toml → cargo test
  3. If nothing matches, or more than one ecosystem matches → fail with an error that asks you to set commands, instead of guessing

For Python, Java, and other stacks with many local conventions, set commands explicitly.

Custom config

Change config only when the default is wrong. Put this in the profile’s cordis.patch.yml (it replaces that plugin’s entire config):

- id: dsh-verify-gate
  name: dsh-verify-gate
  config:
    commands:
      - id: test
        run: pytest -q
    autoDetect: true
    sandboxMode: danger-full-access

sandboxMode defaults to danger-full-access so package managers can use a global store. If you tighten the sandbox, confirm the verify commands still run for real.

Everyday entry points

Goal Entry
Run verification verify_run or /verify run
Inspect gate status verify_status or /verify
Conclude verify_conclude (needs a green, non-dirty, non-expired receipt)

Receipts are stored under <workspace>/.dsh/verify-receipts/. Most application repos should ignore that directory.

License

MIT