dsh-update-notifier
Red-dot update checker for DeepSeek Harness (dsh).
Shows nothing at all while your install is current. When the published
@deepseek-ai/dsh latest version on npm
is newer than your installed one, a DSH-native badge (red StateDot + version label) appears
in the sidebar footer. Clicking it opens a modal with current → latest, last-checked time, and:
copy the update command for your install mode, ignore this version, or snooze.
This is a community plugin, not an official DeepSeek product.
How it works
- Host half (
src/index.js): resolves your installed DSH version once at startup, polls the npm registry (default: first check 10s after startup, then every 6h), and serves the cached decision onGET /dsh-update-check(with anupdateHintthat matches your install mode:npm exec @deepseek-ai/dsh@latest webfor npx-cache installs,npm install -g @deepseek-ai/dsh@latestotherwise) via the optionalwebServerservice. Headless compositions are unaffected. - Browser half (
client/client.js): registers asidebar.footer.actionslot entry rendered with the officialui-primitives(StateDot/Button/Modal); it rendersnullunless an update is available. "Ignore" persists inlocalStorageuntil a newer version appears; "Later" hides it until the next fresh check result.
Compatibility
- Verified against dsh 0.1.0-rc.5 (monorepo dev clone, full web boot + endpoint E2E) and 0.1.0-rc.6 (npm-installed, host boots, load-level headless test clean). Last verified: 2026-08-15.
- Tracks the npm
latestdist-tag of@deepseek-ai/dsh, so it stays version-agnostic; no pin to a specific dsh commit is required.
Install / Uninstall
Install (npm by name, git URL, or local dir all work):
dsh plugin --profile web add dsh-update-notifier
dsh plugin --profile web add https://github.com/arvin-yd/dsh-update-notifier.git
dsh plugin --profile web add /path/to/this/repo
Uninstall / remove:
dsh plugin --profile web rm dsh-update-notifier
The plugin activates at the next dsh web start (a restart is required after install).
Quick start
Install into the
webprofile (above) and restart:dsh --profile web --port <port>.Sanity-check the host half:
curl http://127.0.0.1:<port>/dsh-update-check # {"state":"up-to-date","current":"0.1.0-rc.6","latest":"0.1.0-rc.6","fetchedAt":...,"error":null,"updateHint":"..."}Nothing appears in the UI while you are current. When npm
latestexceeds your installed version, a red-dot badge shows in the sidebar footer; the modal offers copy-update-command / ignore / snooze.
Config
Defaults live in cordis.patch.yml; override in $DSH_HOME/profiles/web/cordis.patch.yml:
- id: dsh-update-notifier
config:
checkIntervalMs: 21600000 # host re-check interval (default 6h)
timeoutMs: 5000 # registry fetch timeout (ms)
Permissions & data
- Reads: your dsh install location (to resolve the installed version), the npm public
registry over HTTPS (
registry.npmjs.org— metadata only, no credentials sent). - Writes: nothing on disk; the browser half stores only the ignored-version string in
localStorage(dsh-update-notifier.ignoredVersion). - No telemetry, no analytics, no third-party calls beyond the npm registry.
Troubleshooting
- Badge never appears — expected when you are on the latest version; verify via the
endpoint above (
statemust beupdate-available). currentisnull/ stateunknown— run dsh through its normal entrypoint (dsh web/npm exec @deepseek-ai/dsh web); the version probe walks up from the running bin, plugin directory, and enclosing@deepseek-ai/dsh*package.- state
error— registry fetch failed (offline/blocked); check the dsh host log for[dsh-update-notifier] check failed: ...; it retries everycheckIntervalMs. - Rollback —
dsh plugin --profile web rm dsh-update-notifierremoves the plugin.
Development
pnpm install
pnpm test
License & security
MIT. To report a security issue privately, use GitHub's private vulnerability reporting.
No comments yet. Be the first to write one.