dsh-catalog
开发工具 活跃维护

dsh-catalog

PerryLink/dsh-catalog

作为PerryLink生态标准目录源,可提供标准化的社区插件、工具类目录资源,统一资源检索与分发规范,方便开发者快速获取适配资源,降低集成成本。

0
Stars 标星
0
Forks 分支
0
Watchers 关注
0
Open Issues
JavaScript
主要语言
Apache-2.0
开源协议
81 KB
仓库大小
18 天前
最后推送
一键安装扩展 / 插件指令
dsh plugin --profile web add github:PerryLink/dsh-catalog
git clone https://github.com/PerryLink/dsh-catalog.git
git clone git@github.com:PerryLink/dsh-catalog.git
README.md main

dsh-catalog

A DSH Community Market standard catalog source for the PerryLink DeepSeek Harness plugin family: 34 npm packages, generated from the npm registry, validated against the public v1 contract schemas.

  • Manifest: catalog-source.json (generated; see Deploy)
  • Provider page: artifacts/v1/plugins.json (generated)
  • Source of truth: data/packages.json (npm name → repo → display name → categories) + data/npm-snapshot.json (npm registry snapshot)
  • Generator / validator: scripts/build-catalog.mjs, scripts/validate.mjs
  • Deploy: live at https://perrylink-dsh-catalog.perrylink.workers.dev (Cloudflare Workers, automated via deploy.yml; Vercel static alternative in vercel.json; Deno unit deploy/deno-worker.js as manual alternative)

Compliance notes

  • Contract: catalog-provider-contract.md (v1, manifestVersion/schemaVersion 1.0.0). The schemas are vendored nowhere in this repo; scripts/validate.mjs mirrors the structural rules of catalog-source.schema.json and catalog-provider-page.schema.json and the cross-field rules (unique item ids, npm name pattern, no install commands in items, HTTPS repository URLs, page shape).
  • The minimal valid profile is used: query.supported = [], defaultLimit = maxLimit = 50, sorts = []. The endpoint returns the complete bounded page (34 items ≤ 50), so DSH Desktop scans it in one request and runs search/filtering over its local index.
  • Every item carries package.registry = "npm" + package.name and a canonical repository.url; no install commands, shell fragments or executable data are ever emitted.
  • Every item also carries a same-origin media.icon (/icons/<slug>.png, generated deterministically by scripts/build-icons.mjs); the Worker serves the PNGs itself, so the icons stay on the catalog origin as the market media rule requires.
  • The manifest endpoint and the manifest itself must share one HTTPS origin (market rule). The generated placeholder endpoint https://replace-with-deploy-origin.invalid/... is replaced by the real deploy origin at deploy time — do not register the placeholder URL in DSH Desktop.

Build

node scripts/build-catalog.mjs            # placeholder endpoint
node scripts/validate.mjs                 # structural checks
node scripts/build-catalog.mjs https://<your-project>.deno.dev   # real origin

build-catalog.mjs writes the manifest and provider page to the repo root and mirrors both into deploy/, so deploy/deno-worker.js is a self-contained Deno Deploy unit (its ./ imports always resolve).

data/npm-snapshot.json is refreshed UTF-8-safely with:

node scripts/refresh-snapshot.mjs   # re-fetch every package from registry.npmjs.org

Deploy

Live: https://perrylink-dsh-catalog.perrylink.workers.dev (Cloudflare Workers, deployed automatically by the deploy workflow).

Automated channels — the workflow rebuilds the manifest with the live origin, validates, then deploys; each channel skips gracefully when its token secret is absent:

  • Cloudflare Workers (active): deploy/wrangler.toml + deploy/cloudflare-worker.js. Requires CLOUDFLARE_API_TOKEN + CLOUDFLARE_ACCOUNT_ID secrets. Two-pass deploy: first uploads the placeholder-origin worker, reads the assigned *.workers.dev URL, rebuilds the manifest pinned to that origin, and redeploys. Falls back to Cloudflare Pages (.pages.dev) when workers.dev is unavailable.
  • Vercel: vercel.json rewrite /v1/pluginsartifacts/v1/plugins.json. Requires VERCEL_TOKEN.
  • Deno Deploy (manual): self-contained deploy/deno-worker.js; rebuild with node scripts/build-catalog.mjs https://<your-project>.deno.dev before deploying.

The site serves GET /catalog-source.json and GET /v1/plugins as application/json on one HTTPS origin.

Use in DSH Desktop

Open the built-in Market → Sources → add source → paste the manifest URL https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json → select it. Browsing is read-only; installation of any listed plugin goes through the Market's own npm-identity verification and user confirmation.

A listing in this catalog is metadata, not a security review. The same plugins also have evidence records in dsh-plugin-certification and MCP access via dsh-cert-mcp.


中文说明

PerryLink 全家桶的 DSH Community Market 标准目录源:34 个 npm 包,由 npm registry 生成,按公开 v1 契约做结构校验。已上线 Cloudflare Workers(perrylink-dsh-catalog.perrylink.workers.dev,deploy workflow 自动部署;Vercel 静态重写与 Deno Deploy 为备选通道)。每个条目还带同源 media.icon 图标(/icons/*.png,由 scripts/build-icons.mjs 确定性生成)。在 DSH Desktop 的 市场 → Sources 里添加 manifest URL 即可浏览(浏览只读;安装仍走市场自身的 npm 身份校验与用户确认)。生成产物中的占位域名 replace-with-deploy-origin.invalid 在部署时替换,请勿直接注册占位地址。

License

Apache-2.0. Catalog data derives from the npm registry and the PerryLink plugin repositories.