dsh-plugin-github-workflows
English | 简体中文
Complete GitHub workflows for DeepSeek Harness (DSH), built on the GitHub CLI — commits, pull requests, issues, releases, Actions, repositories, Codespaces and search, in one zero-dependency plugin with 11 typed tools and 80+ actions.
Why
- Typed, not stringly — every operation is a JSON-schema-typed tool with
an
actionenum; commands are built as argv arrays and spawned without a shell, so model-supplied text can never inject shell syntax. - Safe by default — destructive operations (merge, delete, force-push,
rebuild, workflow dispatch…) require an explicit
confirm: true, with a config master switch (allowDestructive) to hard-disable them all. - Zero-config auth — reuses gh's login,
GH_TOKEN, or falls back to the credential already stored in git's credential helper. If you cangit push, the plugin just works. - Zero dependencies — Node built-ins only; installs from a git repo or a local folder with nothing to resolve or build.
Tools
| Tool | Coverage |
|---|---|
github_auth |
status, PAT login (token via stdin, never logged), refresh, account switch |
github_repo |
view / list / create / clone / fork / edit / sync / rename / archive / delete |
github_pr |
create / list / view / diff / checks / comment / review / merge / close / reopen / edit / ready / checkout / status |
github_issue |
create / list / view / status / comment / close (reason) / reopen / edit / develop (linked branch) |
github_commit |
read-only commit browsing (list / view / compare / branches) via the GitHub REST API |
github_release |
create (notes, generated notes, assets) / list / view / upload / download / edit / delete |
github_actions |
runs: list / view / log / watch / rerun / cancel / delete; workflows: list / view / dispatch |
github_codespace |
list / create / non-interactive ssh / cp / code / stop / rebuild / logs / delete |
github_search |
repos / issues / prs / code / commits |
github_api |
any REST/GraphQL request (escape hatch: labels, milestones, projects, gists, orgs, …) |
github_git |
local git: status / add / commit / push / pull / fetch / branch / log / remote |
github_cli |
raw gh passthrough, off by default (registered only with allowRaw: true) |
Install
Requires: DSH, Node >= 18, gh CLI, git, and any one auth source (below).
Ask the agent to call plugin_manager, or use GUI Settings → Plugins →
Install:
install_bundle → target: github:Planckbaka/dsh-plugin-github-workflows
Quick start
A typical "code → PR → CI → release" loop after installing:
github_auth action: status ← verify authentication
github_git action: status ← what changed?
github_git action: add paths: ["src"]
github_git action: commit message: "Fix ..."
github_git action: push setUpstream: true
github_pr action: create title: "Fix ..." fill: true
github_actions action: run_watch runId: <id> ← follow CI to green
github_pr action: merge mergeMethod: squash, deleteBranch: true, confirm: true
github_release action: create tag: v1.1.0, generateNotes: true, confirm via notes
Authentication
The plugin reuses whatever credentials you already have, with an automatic fallback chain:
- gh already logged in (
gh auth login) → used directly; GH_TOKENin the environment (e.g.~/.dsh/.env) → picked up natively by gh;- git credential fallback — when gh is not logged in, the plugin reads
the
github.comcredential from git's credential helper (Git Credential Manager) once, prompts disabled, and injects it asGH_TOKEN.
You can also call github_auth with action setup and a PAT (piped via
stdin, never logged). See SECURITY.md for the full credential
model.
Configuration
All keys optional — defaults live in lib/index.js; override them in the
plugin's config section (see cordis.patch.yml).
| Key | Default | Meaning |
|---|---|---|
ghPath |
"" |
Override path of the gh executable (PATH by default) |
gitPath |
"" |
Override path of the git executable (github_git + credential fallback) |
defaultRepo |
"" |
Default owner/name repository |
timeoutMs |
60000 |
Timeout for normal commands |
watchTimeoutMs |
300000 |
Timeout for watch/log actions |
maxOutputBytes |
65536 |
Output truncation threshold; overflow goes to a spill file |
allowRaw |
false |
Register the github_cli passthrough tool |
allowDestructive |
true |
Master switch for destructive actions |
env |
{} |
Extra environment variables (e.g. GH_HOST for GHES) |
Development
git clone https://github.com/Planckbaka/dsh-plugin-github-workflows.git
npm install --no-save typescript@5 @types/node # optional: type checking
npx tsc --noEmit # JSDoc types, no build step
npm test && npm run test:integration
Layout, the dsh-tools JSON-Schema subset rule, and the full contributor guide are in CONTRIBUTING.md.
Community standards
Contributing · Security policy · Code of conduct · Changelog · Issues · Discussions
No comments yet. Be the first to write one.