README来源: main@8660cb60
dsh-git-forge
DeepSeek Harness community plugin: forge accounts + per-project grants + push policy in dsh-better-sidebar.
- Account library: GitHub / Gitea / GitLab / Gitee / Bitbucket
- Project grants (
projectPathKey= workspace cwd) - Push guard: blocks bash
git push/git remote add|set-urlto non-granted hosts - Tokens in
$DSH_HOME/git-forge/secrets.json(0600) — never in model context - Model tool
GitForge(read-only policy) - Agent HTTPS git: after sidebar grants, agent bash
git fetch/pushcan use the matching account via a Host-only credential helper (tokens never enter the model; R1 = exactly one granted token account per host) - UI aligned with dsh-ssh-tunnel
SSH remotes and system gh auth still use local SSH/gh. HTTPS under DSH agent shells is filled by this plugin’s helper from project grants; the push guard still decides where a project may push.
Requirements
- DSH web profile with dsh-better-sidebar (≥ 0.12)
- Node.js 18+
Install
macOS / Linux (Git Bash / WSL on Windows also works):
curl -fsSL https://raw.githubusercontent.com/thirsty5034/dsh-git-forge/main/scripts/install.sh | bash
Windows (PowerShell 5.1+ / pwsh):
irm https://raw.githubusercontent.com/thirsty5034/dsh-git-forge/main/scripts/install.ps1 | iex
Or via DSH CLI directly (GitHub source until the package is on npm):
export DSH_HOME=${DSH_HOME:-$HOME/.dsh}
dsh plugin --profile web add "dsh-git-forge@github:thirsty5034/dsh-git-forge"
dsh --profile web --dump-config | grep git-forge
After install: restart DSH web, then hard-refresh the browser (Cmd/Ctrl+Shift+R).
# pin ref
curl -fsSL .../install.sh | bash -s main --restart
bash scripts/install.sh --from npm 0.1.1 # after npm publish
# local checkout
dsh plugin --profile web add "dsh-git-forge@link:/path/to/dsh-git-forge"
# or: ./scripts/sync-to-dsh.sh && dsh plugin add "dsh-git-forge@link:$DSH_HOME/local-plugins/dsh-git-forge"
Discoverability
- GitHub topics:
dsh-plugin,deepseek-harness,dsh(required for dsh.so auto-index) - Install from GitHub (current): see Install above
- Store listings may lag crawlers; source of truth is this repository
Data
Under $DSH_HOME/git-forge/:
| File | Purpose |
|---|---|
accounts.json |
Account metadata (no tokens) |
secrets.json |
Tokens (0600) |
grants.json |
projectPathKey → accountIds[] + enforce policy |
Sidebar
- Project access — accounts for the current project + enforce push
- Accounts — CRUD, API token probe
- Policy — allowed gitHosts; unbound-project default
Model tool
GitForge action=list_accounts
GitForge action=get_policy
GitForge action=list_project_accounts
GitForge action=check_remote url=git@github.com:org/repo.git
Agent HTTPS and project path
- Grant key = DSH session workspace (
DSH_GIT_FORGE_PROJECTin agent shells), not nested package path - Helper resolution:
env→ exact cwd → walk parents under/workspace - R1: auto-fill only with exactly one granted token account for that host
- Push guard checks inline URLs and bare
git push/git push origin(resolves remote URL)
Security
- Tokens never appear in tool/API results or model context
- Push policy is enforced in Host
tools.guard - With no project grants, push is not blocked by default (progressive enablement); helper also supplies no credentials
Development
npm test
npm run check
./scripts/sync-to-dsh.sh # optional: copy into $DSH_HOME/local-plugins
License
MIT — see LICENSE.
还没有评论,来写第一条。