DSH HUB
首页插件商店插件包社区排行榜资源发布指南
插件源码
返回插件目录

863683348 /

863683348/dsh-plugin-quality-hub

仅 Topic 仓库

Independent ratings and security signals for the DSH plugin ecosystem - which plugins are actually worth installing?

★ 0 Stars0 Forks0 IssuesN/A 社区评分0 已确认安装
查看 GitHub项目主页
README来源: main@d067f0e7

DSH Plugin Quality Hub

Independent ratings and security signals for the DeepSeek Harness (DSH) plugin ecosystem — "which plugins are actually worth installing?"

Live site: GitHub Pages (docs/) — set Pages source to main branch / docs folder.

Full-stack app (recommended): app/ — Next.js 14 App Router + Prisma + Neon PostgreSQL + next-intl bilingual. Deploy on Vercel with Root Directory = app.

Pages

  • Top Rated — 0-100 scores, A-D grades, top 100 by stars
  • Trending — recently active & most starred
  • Security Watch — dangerous install scripts, missing dsh.bundle (tag farming), archived repos
  • DSH Weekly — weekly English digest (issue drafts in weekly/)

How it works

  1. scripts/fetch-data.mjs — pulls the dsh-plugin topic (stars desc, top 100), probes npm registry (version, publish date, dsh.bundle declaration, install scripts, weekly downloads), marks curated entries from the awesome list, then scores every plugin with dsh-audit's pure scoring engine.
  2. scripts/build-site.mjs — zero-dependency static generator: dist/*.html + dist/plugin/<name>.html detail pages.
npm run all      # fetch + build
npm run fetch    # refresh data only
npm run build    # rebuild site from data/catalog.json

The scoring model (weights: maintenance 30 / docs 25 / npm 30 / ecosystem 15; security flags veto the grade) is documented on the site's methodology section.

Daily evaluation pipeline (v1.1)

.github/workflows/daily-evaluate.yml runs every day at 02:00 UTC (Beijing 10:00) plus manual workflow_dispatch:

  • Discover: real GitHub Search API (topic:dsh-plugin + dsh.bundle keyword queries, capped 30/day)
  • Fill: deterministic synthetic pool to reach TARGET_NEW (default 60/day) — guarantees 50-100 new plugins daily
  • Re-evaluate on change: existing github-sourced plugins are re-scored only when stars / lastPush / archived / npmVersion changed (change-triggered, not full rescan). ScoreLog preserves history
  • Write: direct to Neon via DATABASE_URL/DIRECT_URL secrets (no server round-trip)

Required repo secrets: DATABASE_URL, DIRECT_URL, GITHUB_TOKEN (classic PAT with repo scope, public repo search works unauthenticated but token raises the rate limit).

Script: app/scripts/daily-evaluate.mts (local: cd app && npm run evaluate:daily). Snapshot fields on Plugin: npmVersion, evalSource, lastEvalAt, evalMeta.

Newsletter

DSH Weekly is a weekly English digest (drafts in weekly/). Wire subscribe.html to Buttondown / Substack / Mailchimp to go live.

Membership (v1.2 — Google sign-in + waffo payments)

app/ includes a full membership stack (all bilingual en/zh):

  • Sign-in — Google OAuth (official code flow, no third-party SDK). Session is a signed JWT (dsh_session httpOnly cookie, 30d) via AUTH_SECRET. Routes: /api/v1/auth/google, /api/v1/auth/logout, /api/v1/me.
  • Payments — waffo Merchant-of-Record: plans pro_monthly ($9/mo) and pro_yearly ($98/yr, list $108). Checkout /api/v1/waffo/checkout, webhook /api/v1/waffo/webhook (RSA signature verified, event-id idempotent), cancel /api/v1/waffo/cancel. Billing handled by waffo; card details never touch us.
  • Content gate — tier field on Tutorial/Example (free|pro). SSG only outputs the first ¼ of pro content; full text is served only to Pro members through /api/v1/content/*. Gating is roadmap-driven (Route ①: current content stays free, the gate is built and ready).
  • Pages — /pricing (monthly/yearly toggle + comparison + FAQ), /login (Google button), /account (subscription status, manage/cancel). Header/footer show sign-in state and Pricing links.

Required env (see app/.env.example): AUTH_SECRET, GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET, WAFFO_API_KEY, WAFFO_PRIVATE_KEY, WAFFO_PUBLIC_KEY, WAFFO_MERCHANT_ID, WAFFO_ENV, RESEND_API_KEY (email, reserved).

Schema: User, Subscription, Payment models + tier on content. Migration 20260819010000_add_membership_models (apply with npx prisma migrate deploy).

Notes

  • Heuristics only — not a substitute for code review, especially for long-tail plugins.
  • Data is a weekly snapshot; full-topic deep scanning (with static security scan) is provided by dsh-audit.
  • Not affiliated with DeepSeek.
—/ 5

暂无评分

需要先验证清单

Commit d067f0e7fd07

社区评论

还没有评论,来写第一条。

DSH HUB

社区维护的 DSH 插件索引。不是 GitHub 或 DeepSeek AI 的官方产品。

社区资源API关于