docs(market): initialize community market shell

This commit is contained in:
t4we fan
2026-08-17 01:41:05 +08:00
parent 2148432273
commit 9c2d915154
28 changed files with 702 additions and 28 deletions
@@ -1,5 +1,5 @@
# Bilingual-pair consistency record: the git blob hash of each side as of the last
# confirmed-consistent state. Both languages carry equal authority. Update both files
# and re-record their hashes with git hash-object after editing either side.
2026-08-15-pinned-upstream-and-isolated-yarn-workspace.md: e78fffa92838ab4f0888c25fad5ba6cbfee58480
2026-08-15-pinned-upstream-and-isolated-yarn-workspace.zh.md: eb83f087978faba0f504fe3a393894fa0d072f31
2026-08-15-pinned-upstream-and-isolated-yarn-workspace.md: a3b85e87f59aa3efc709916cbd88c2b64e014123
2026-08-15-pinned-upstream-and-isolated-yarn-workspace.zh.md: e78485870696ab27d7ef9aa14ea5d01f83446a60
@@ -12,17 +12,17 @@ DSH Desktop needs the exact official DeepSeek Harness source for review while th
[`deepseek-harness/`](../../../../deepseek-harness/) is a Git submodule pinned to the official repository and exact commit recorded in [`upstream.json`](../../../../upstream.json). Desktop branches treat the submodule as read-only. An upstream update changes the gitlink and metadata in a dedicated commit.
The outer README files and assets are product-owned and preserve the established DSH Desktop landing page from `anywhere-labs/deepseek-harness-desktop`. They are not derived from the official source submodule. Package-level setup and release documentation belongs to [`dsh-plugin-desktop/README.md`](../../../../dsh-plugin-desktop/README.md); the proposed community interoperability contract belongs to [`dsh-community-fabric/README.md`](../../../../dsh-community-fabric/README.md).
The outer README files and assets are product-owned and preserve the established DSH Desktop landing page from `anywhere-labs/deepseek-harness-desktop`. They are not derived from the official source submodule. Package-level setup and release documentation belongs to [`dsh-plugin-desktop/README.md`](../../../../dsh-plugin-desktop/README.md); the proposed community interoperability contract belongs to [`dsh-community-fabric/README.md`](../../../../dsh-community-fabric/README.md); the proposed market product and trust boundary belongs to [`dsh-community-market/README.md`](../../../../dsh-community-market/README.md).
The outer repository is a Yarn 4 workspace using the `node_modules` linker. Its owned workspace members are [`dsh-plugin-desktop`](../../../../dsh-plugin-desktop/) and [`dsh-community-fabric`](../../../../dsh-community-fabric/). Fabric begins as a private documentation scaffold: it has no runtime entry, SDK, schema release, or DSH bundle until the community Draft has reviewed contracts and conformance evidence. The upstream checkout remains an independent pnpm workspace under its own [package-manager decision](../../../../deepseek-harness/.agents/notes/implemented/process/2026-06-16-pnpm-over-yarn.md). Root `upstream:*` scripts use Yarn's portable shell to enter the submodule before invoking its pinned pnpm release through Corepack.
The outer repository is a Yarn 4 workspace using the `node_modules` linker. Its owned workspace members are [`dsh-plugin-desktop`](../../../../dsh-plugin-desktop/), [`dsh-community-fabric`](../../../../dsh-community-fabric/), and [`dsh-community-market`](../../../../dsh-community-market/). Fabric begins as a private documentation scaffold with no runtime entry, SDK, schema release, or DSH bundle until the community Draft has reviewed contracts and conformance evidence. Market also begins as a private documentation scaffold with no runtime entry or DSH bundle until the proposed shell has implementation and Loader evidence. The upstream checkout remains an independent pnpm workspace under its own [package-manager decision](../../../../deepseek-harness/.agents/notes/implemented/process/2026-06-16-pnpm-over-yarn.md). Root `upstream:*` scripts use Yarn's portable shell to enter the submodule before invoking its pinned pnpm release through Corepack.
Normal desktop builds resolve published DSH packages from the npm registry instead of linking source from the submodule. `upstream.json` records the source version and the runtime package family independently. The pinned public GitHub source reports `0.1.0-rc.5`, while the desktop runtime uses the published `0.1.0-rc.6` family; the repository does not invent a source commit for an npm artifact that does not publish one.
`yarn check:layout` rejects a changed submodule URL, commit, working tree, package-manager boundary, owned workspace member list, or DSH runtime family. The root check runs the lightweight Fabric documentation gate before the complete desktop gate. CI initializes submodules, installs the outer workspace immutably, runs the owned-package checks, and exercises the upstream command path on Windows.
`yarn check:layout` rejects a changed submodule URL, commit, working tree, package-manager boundary, owned workspace member list, or DSH runtime family. The root check runs the lightweight Fabric and Market documentation gates before the complete desktop gate. CI initializes submodules, installs the outer workspace immutably, runs the owned-package checks, and exercises the upstream command path on Windows.
## Verification
Acceptance requires `yarn check:layout`, `yarn upstream:version`, `yarn install --immutable`, and `yarn check` to pass. The Fabric gate checks its private manifest, bilingual hashes, and documentation links. The Loader smoke in the desktop gate activates the built desktop package through Cordis without opening an Electron window; Fabric intentionally has no Loader entry in its documentation-only phase.
Acceptance requires `yarn check:layout`, `yarn upstream:version`, `yarn install --immutable`, and `yarn check` to pass. The Fabric and Market gates check their private manifests, bilingual hashes, and documentation links. The Loader smoke in the desktop gate activates the built desktop package through Cordis without opening an Electron window; neither community package has a Loader entry in its documentation-only phase.
## Alternatives considered
@@ -38,6 +38,6 @@ Acceptance requires `yarn check:layout`, `yarn upstream:version`, `yarn install
## Consequences
Desktop changes have two explicitly owned package trees, and the official checkout remains directly comparable with its remote commit. The outer landing page presents DSH Desktop, the desktop README owns application usage, and the Fabric README owns the proposed community contract boundary. Product installs and checks are reproducible from the outer Yarn lockfile, while upstream verification continues to use its own pnpm lockfile.
Desktop changes have three explicitly owned package trees, and the official checkout remains directly comparable with its remote commit. The outer landing page presents DSH Desktop, the desktop README owns application setup and release usage, the Fabric README owns the proposed community contract boundary, and the Market README owns the proposed market boundary. Product installs and checks are reproducible from the outer Yarn lockfile, while upstream verification continues to use its own pnpm lockfile.
Clones must initialize the submodule, and contributors maintain two intentionally separate package-manager caches. Source-pin updates and runtime-family updates require separate evidence because a public GitHub revision and a published npm family may not correspond.
@@ -12,17 +12,17 @@ DSH Desktop 需要保留可供审查的 DeepSeek Harness 官方精确源码,
[`deepseek-harness/`](../../../../deepseek-harness/) 是 Git 子模块,固定到 [`upstream.json`](../../../../upstream.json) 记录的官方仓库和精确提交。桌面分支把该子模块视为只读内容。更新上游时,在独立提交中同时修改 gitlink 与元数据。
外层 README 文件和资源由产品仓库拥有,并保留 `anywhere-labs/deepseek-harness-desktop` 已有的 DSH Desktop 落地页;这些内容不从官方源码子模块派生。Desktop package 的初始化与发行文档属于 [`dsh-plugin-desktop/README.md`](../../../../dsh-plugin-desktop/README.md);规划中的社区互操作 contract 属于 [`dsh-community-fabric/README.zh.md`](../../../../dsh-community-fabric/README.zh.md)。
外层 README 文件和资源由产品仓库拥有,并保留 `anywhere-labs/deepseek-harness-desktop` 已有的 DSH Desktop 落地页;这些内容不从官方源码子模块派生。Desktop package 的初始化与发行文档属于 [`dsh-plugin-desktop/README.md`](../../../../dsh-plugin-desktop/README.md);规划中的社区互操作 contract 属于 [`dsh-community-fabric/README.zh.md`](../../../../dsh-community-fabric/README.zh.md);规划中的社区市场产品与信任边界属于 [`dsh-community-market/README.zh.md`](../../../../dsh-community-market/README.zh.md)。
外层仓库是使用 `node_modules` linker 的 Yarn 4 工作区。自有 workspace 成员是 [`dsh-plugin-desktop`](../../../../dsh-plugin-desktop/) 和 [`dsh-community-fabric`](../../../../dsh-community-fabric/)。Fabric 从私有文档初始化工程开始:在社区 Draft 拥有经过评审的 contract 与一致性证据前,不提供 runtime 入口、SDK、正式 schema 或 DSH bundle。上游 checkout 按照自己的[包管理器决策](../../../../deepseek-harness/.agents/notes/implemented/process/2026-06-16-pnpm-over-yarn.zh.md)保持为独立的 pnpm 工作区。根目录的 `upstream:*` 脚本通过 Yarn portable shell 进入子模块,再由 Corepack 调用上游固定的 pnpm 版本。
外层仓库是使用 `node_modules` linker 的 Yarn 4 工作区。自有 workspace 成员是 [`dsh-plugin-desktop`](../../../../dsh-plugin-desktop/)、[`dsh-community-fabric`](../../../../dsh-community-fabric/) 和 [`dsh-community-market`](../../../../dsh-community-market/)。Fabric 从私有文档初始化工程开始:在社区 Draft 拥有经过评审的 contract 与一致性证据前,不提供 runtime 入口、SDK、正式 schema 或 DSH bundle。Market 同样从私有文档初始化工程开始:在市场壳具备实现和 Loader 证据前,不提供运行入口或 DSH bundle。上游 checkout 按照自己的[包管理器决策](../../../../deepseek-harness/.agents/notes/implemented/process/2026-06-16-pnpm-over-yarn.zh.md)保持为独立的 pnpm 工作区。根目录的 `upstream:*` 脚本通过 Yarn portable shell 进入子模块,再由 Corepack 调用上游固定的 pnpm 版本。
普通桌面构建从 npm registry 解析已发布的 DSH 包,不从子模块链接源码。`upstream.json` 分别记录源码版本和运行时包 family。固定的 GitHub 公开源码声明为 `0.1.0-rc.5`,桌面运行时使用已发布的 `0.1.0-rc.6` family;当 npm artifact 没有发布对应源码提交时,仓库不会虚构两者的对应关系。
`yarn check:layout` 会拒绝变化的子模块 URL、提交、工作树、包管理边界、自有 workspace 成员列表或 DSH 运行时 family。根检查会先运行轻量的 Fabric 文档门禁,再运行完整 Desktop 门禁。CI 会初始化子模块,以 immutable 模式安装外层工作区,运行自有 package 检查,并在 Windows 上执行上游命令路径。
`yarn check:layout` 会拒绝变化的子模块 URL、提交、工作树、包管理边界、自有 workspace 成员列表或 DSH 运行时 family。根检查会先运行轻量的 Fabric 和 Market 文档门禁,再运行完整 Desktop 门禁。CI 会初始化子模块,以 immutable 模式安装外层工作区,运行自有 package 检查,并在 Windows 上执行上游命令路径。
## Verification
验收要求 `yarn check:layout`、`yarn upstream:version`、`yarn install --immutable` 和 `yarn check` 全部通过。Fabric 门禁检查私有 manifest、双语 hash 和文档链接。Desktop 门禁中的 Loader smoke 会通过 Cordis 激活构建后的桌面包,但不会打开 Electron 窗口;文档阶段的 Fabric 刻意没有 Loader 入口。
验收要求 `yarn check:layout`、`yarn upstream:version`、`yarn install --immutable` 和 `yarn check` 全部通过。Fabric 与 Market 门禁会检查各自的私有 manifest、双语 hash 和文档链接。Desktop 门禁中的 Loader smoke 会通过 Cordis 激活构建后的桌面包,但不会打开 Electron 窗口;两个社区 package 在文档阶段都刻意没有 Loader 入口。
## Alternatives considered
@@ -38,6 +38,6 @@ DSH Desktop 需要保留可供审查的 DeepSeek Harness 官方精确源码,
## Consequences
桌面改动有两个边界明确的自有 package tree,官方 checkout 可以与其远端提交直接比较。外层落地页展示 DSH Desktop,Desktop README 负责应用使用,Fabric README 负责规划中的社区 contract 边界。产品安装与检查可由外层 Yarn lockfile 复现,上游验证则继续使用自己的 pnpm lockfile。
桌面改动有三个边界明确的自有 package tree,官方 checkout 可以与其远端提交直接比较。外层落地页展示 DSH Desktop,Desktop README 负责应用初始化与发行说明,Fabric README 负责规划中的社区 contract 边界,Market README 负责规划中的市场边界。产品安装与检查可由外层 Yarn lockfile 复现,上游验证则继续使用自己的 pnpm lockfile。
克隆时必须初始化子模块,贡献者也需要维护两套有意隔离的包管理器缓存。GitHub 公开修订与 npm 发布 family 可能不对应,因此源码 pin 更新和运行时 family 更新需要分别提供验证证据。
+1
View File
@@ -5,6 +5,7 @@ This repository owns the desktop product around an unmodified DeepSeek Harness c
- `deepseek-harness/` is a pinned upstream Git submodule. Never edit files inside it from a desktop feature branch.
- `dsh-plugin-desktop/` owns the Cordis Host and Client faces, Electron bootstrap, packaging, and release tests.
- `dsh-community-fabric/` owns the community interoperability RFC. Until schemas and a reviewed reference adapter exist, it remains a private documentation scaffold and must not declare loadable DSH or package entry points.
- `dsh-community-market/` owns the community-market shell. Until its runtime is implemented, it remains a private documentation scaffold and must not declare loadable DSH or package entry points.
- The outer repository and all owned packages use the root Yarn release with `nodeLinker: node-modules`.
- The upstream submodule keeps its own pnpm workspace. Run upstream commands through the root `upstream:*` scripts, whose Yarn portable-shell commands enter the submodule before invoking Corepack.
- Compatibility mode must run the upstream default client without overrides. Advanced presentation belongs to desktop-owned client plugins and may replace documented slots or services through profile composition.
+2 -1
View File
@@ -17,6 +17,7 @@ DSH is built around plugins. If you write plugins, start with:
- [Plugin development](docs/plugin-development.en.md): how to write ordinary DSH plugins and Desktop plugins.
- [DSH plugin ecosystem manifesto](docs/plugin-ecosystem.en.md): our vision of an open, composable, sustainable ecosystem, and the three principles — composition first, declare clearly, compatibility first.
- [DSH Community Fabric Draft](dsh-community-fabric/README.md): join the public discussion of manifests, capabilities, Host Descriptors, and event contracts.
- [Community Market design](dsh-community-market/docs/market-shell.md): how the future market will discover plugins and why listing is not a security review.
Plugins that follow the manifesto coexist better with other plugins and will be easier to discover and trust in the marketplace when it ships.
@@ -34,7 +35,7 @@ corepack yarn dev # launch the application when a graphical session is avail
### Repository boundaries (please read before starting)
- `deepseek-harness/` is the pinned upstream submodule. **Desktop development never edits files inside it**; upstream updates land through separate pin commits.
- Desktop code lives in `dsh-plugin-desktop/`; `dsh-community-fabric/` currently holds only the community-standard Draft and has no loadable runtime. Both owned packages use the outer Yarn workspace.
- Desktop code lives in `dsh-plugin-desktop/`; `dsh-community-fabric/` owns the community-standard Draft and `dsh-community-market/` owns the market-shell design. Both community packages are currently documentation-only and not loadable; all three owned packages share the outer Yarn workspace.
- Builds, typechecks, unit tests, and smoke checks must stay headless-safe.
### Commits and pull requests
+2 -1
View File
@@ -17,6 +17,7 @@ DSH 的核心是插件。如果你写插件,请先阅读:
- [插件开发](docs/plugin-development.md):如何编写普通 DSH 插件和 Desktop 插件。
- [DSH 插件生态倡议书](docs/plugin-ecosystem.md):开放、可组合、可持续的生态愿景,以及组合优先、声明清晰、兼容优先三条原则。
- [DSH Community Fabric Draft](dsh-community-fabric/README.zh.md):参与 Manifest、Capability、Host Descriptor 和事件 contract 的公开讨论。
- [Community Market 设计](dsh-community-market/docs/market-shell.zh.md):未来市场如何发现插件,以及为什么收录不等于安全审核。
遵循倡议书的插件更容易与其他插件共存,也会在未来上线时更容易在插件市场中被发现和信任。
@@ -34,7 +35,7 @@ corepack yarn dev # 有图形环境时启动应用
### 仓库边界(开始前务必了解)
- `deepseek-harness/` 是固定版本的上游子模块,**桌面开发不修改其中的任何文件**;上游内容更新走独立的 pin 提交。
- 桌面代码位于 `dsh-plugin-desktop/`;`dsh-community-fabric/` 当前只保存社区标准 Draft,没有可加载 runtime。两个自有 package 使用外层 Yarn workspace。
- 桌面代码位于 `dsh-plugin-desktop/`;`dsh-community-fabric/` 保存社区标准 Draft,`dsh-community-market/` 保存市场壳设计。两个社区 package 当前都只有文档、尚不可加载,三个自有 package 共用外层 Yarn workspace。
- 构建、类型检查、单元测试和冒烟检查必须保持 headless-safe。
### 提交与 PR
+3 -2
View File
@@ -62,6 +62,7 @@ Ordinary users can start with the [user guide](docs/user-guide.en.md); the devel
| Build ordinary or Desktop plugins | [Plugin development](docs/plugin-development.en.md) |
| Join the unified plugin-contract discussion | [DSH Community Fabric Draft](dsh-community-fabric/README.md) |
| See the research behind the unified plugin framework | [Framework and real-plugin research](dsh-community-fabric/docs/research/mature-plugin-frameworks.md) |
| Read the plugin market product and safety design | [DSH Community Market](dsh-community-market/README.md) |
| See what Desktop plugins can use | [Desktop plugin API](dsh-plugin-desktop/docs/plugin-services.md) |
| Understand how the desktop works | [Architecture](docs/architecture.en.md) |
| Read package-level build and release details | [`dsh-plugin-desktop/README.md`](dsh-plugin-desktop/README.md) |
@@ -81,8 +82,8 @@ Ordinary users can start with the [user guide](docs/user-guide.en.md); the devel
</tr>
<tr>
<td width="50%" valign="top">
<h3><a href="docs/plugin-ecosystem.en.md">Plugin Marketplace</a> <img src="https://img.shields.io/badge/COMING_SOON-F59E0B?style=flat-square" alt="Coming Soon"></h3>
<p>Harness follows an “everything is a plugin” architecture. The desktop marketplace will make it easy to discover, install, update, and manage plugins for models, tools, interfaces, and workflows.</p>
<h3><a href="dsh-community-market/README.md">Plugin Marketplace</a> <img src="https://img.shields.io/badge/IN_DESIGN-F59E0B?style=flat-square" alt="In design"></h3>
<p>We are using DSH Community Market to design plugin discovery, details, and confirmed installation. It currently contains product and safety documentation, not a usable market page.</p>
</td>
<td width="50%" valign="top">
<h3>Co-build the Plugin Ecosystem</h3>
+2 -2
View File
@@ -1,5 +1,5 @@
# Bilingual-pair consistency record: the git blob hash of each side as of the last
# confirmed-consistent state. Both languages carry equal authority. Update both files
# and re-record their hashes after editing either side.
README.md: b62809159392e41baa6f5f551548be937db078ee
README.en.md: 42296aa21cbd0a70d71187060fd6a869a87abe9b
README.md: 1a5692612215c15cb8069c020210231ec5959225
README.en.md: 11fc060ec40d638cdfc6c55e9f02b8e86c7bd8bd
+3 -2
View File
@@ -62,6 +62,7 @@ DSH Desktop 把 [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harne
| 编写普通或 Desktop 插件 | [插件开发](docs/plugin-development.md) |
| 参与统一插件 contract 讨论 | [DSH Community Fabric Draft](dsh-community-fabric/README.zh.md) |
| 了解统一插件框架为什么这样设计 | [成熟框架与真实插件调研](dsh-community-fabric/docs/research/mature-plugin-frameworks.zh.md) |
| 查看插件市场的产品与安全设计 | [DSH Community Market](dsh-community-market/README.zh.md) |
| 了解桌面插件可以使用的能力 | [桌面插件接口说明](dsh-plugin-desktop/docs/plugin-services.zh.md) |
| 了解桌面应用如何工作 | [架构说明](docs/architecture.md) |
| 查阅包级构建与发布细节 | [`dsh-plugin-desktop/README.md`](dsh-plugin-desktop/README.md) |
@@ -81,8 +82,8 @@ DSH Desktop 把 [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harne
</tr>
<tr>
<td width="50%" valign="top">
<h3><a href="docs/plugin-ecosystem.md">插件市场</a> <img src="https://img.shields.io/badge/%E5%8D%B3%E5%B0%86%E6%8E%A8%E5%87%BA-F59E0B?style=flat-square" alt="即将推出"></h3>
<p>Harness 遵循“一切皆插件”的架构。桌面端插件市场将提供插件的发现、安装、更新和管理,让模型、工具、界面与工作流能力按需组合。</p>
<h3><a href="dsh-community-market/README.zh.md">插件市场</a> <img src="https://img.shields.io/badge/%E8%AE%BE%E8%AE%A1%E4%B8%AD-F59E0B?style=flat-square" alt="设计中"></h3>
<p>我们正在通过 DSH Community Market 设计插件发现、详情和确认安装体验。当前只有产品与安全文档,尚未提供可用市场页面。</p>
</td>
<td width="50%" valign="top">
<h3>共建插件生态</h3>
+2 -1
View File
@@ -25,6 +25,7 @@ Ordinary users can start with the [user guide](user-guide.en.md) and never need
| [Community Fabric Draft](../dsh-community-fabric/README.md) | A community interoperability proposal for manifests, capabilities, Host Descriptors, and events |
| [Fabric framework and plugin-needs research](../dsh-community-fabric/docs/research/mature-plugin-frameworks.md) | Mature Koishi, Chrome, and VS Code patterns plus requirements observed in real DSH plugins |
| [VS Code extension-model research](../dsh-community-fabric/docs/research/vscode-extension-model.md) | Implemented declaration, Provider, UI, placement, and lifecycle patterns, with concrete constraints for the Fabric RFC |
| [Community Market design](../dsh-community-market/README.md) | The proposed market shell, catalog source, install confirmation, and safety boundary |
| [Architecture](architecture.en.md) | Electron, Host, loopback Web, profiles, and packaging |
| [Desktop service reference](../dsh-plugin-desktop/docs/plugin-services.md) | Stable `desktopProfiles` and `desktopPnpm` contracts with TypeScript examples |
| [Package reference](../dsh-plugin-desktop/README.md) | Detailed build, runtime, release, and limitation notes |
@@ -43,4 +44,4 @@ The outer repository has two formal product READMEs plus one legacy compatibilit
## Status convention
These pages distinguish shipped behavior, platform limits, and roadmap items. Compatibility mode keeps the upstream default Web client; advanced mode installs the Desktop-owned layout and native materials. The plugin marketplace, mobile remote control, and Channels remain separate roadmap items and are not implied to be part of the current installer.
These pages distinguish shipped behavior, platform limits, and roadmap items. Compatibility mode keeps the upstream default Web client; advanced mode installs the Desktop-owned layout and native materials. The plugin marketplace now has a documentation scaffold in [`dsh-community-market`](../dsh-community-market/README.md), but no usable page or installer; mobile remote control and Channels also remain separate roadmap items and are not implied to be part of the current installer.
+2 -1
View File
@@ -25,6 +25,7 @@
| [Community Fabric Draft](../dsh-community-fabric/README.zh.md) | Manifest、Capability、Host Descriptor 与事件模型的社区互操作提案 |
| [Fabric 框架与插件需求调研](../dsh-community-fabric/docs/research/mature-plugin-frameworks.zh.md) | Koishi、Chrome、VS Code 的成熟模式,以及真实 DSH 插件的功能需求 |
| [VS Code 扩展模型调研](../dsh-community-fabric/docs/research/vscode-extension-model.zh.md) | VS Code 已实现的声明、Provider、UI、运行位置和生命周期模式,以及它们对 Fabric RFC 的具体约束 |
| [Community Market 设计](../dsh-community-market/README.zh.md) | 规划中的插件市场壳、目录来源、安装确认和安全边界 |
| [架构说明](architecture.md) | Electron、Host、loopback Web、profile 和打包之间的关系 |
| [Desktop service 参考](../dsh-plugin-desktop/docs/plugin-services.md) | `desktopProfiles`、`desktopPnpm` 的稳定 contract 和 TypeScript 示例 |
| [包级参考](../dsh-plugin-desktop/README.md) | 完整的构建、运行、发布和已知限制 |
@@ -43,4 +44,4 @@
## 状态约定
文档会明确区分已实现能力、平台限制和 roadmap。Desktop 的兼容模式保留上游默认 Web 客户端;高级模式才安装 Desktop 自有的布局和原生材质。插件市场、手机远程和 Channels 仍是独立 roadmap,不代表当前安装包已经提供这些产品入口。
文档会明确区分已实现能力、平台限制和 roadmap。Desktop 的兼容模式保留上游默认 Web 客户端;高级模式才安装 Desktop 自有的布局和原生材质。插件市场已建立 [`dsh-community-market`](../dsh-community-market/README.zh.md) 文档初始化工程,但尚无可用页面或安装器;手机远程和 Channels 也仍是独立 roadmap,不代表当前安装包已经提供这些产品入口。
+2
View File
@@ -36,6 +36,8 @@ Once the plugin marketplace ships, plugins that follow this manifesto will be ea
Fabric capabilities begin as compatibility, consent, and audit declarations. They do not present in-process JavaScript as a security sandbox. Only a Host with evidence of real isolation may claim technical permission enforcement.
The market is still in its [product and safety design phase](../dsh-community-market/README.md), with no usable page or installer yet. Catalog inclusion means that a project matched catalog rules; it is not a security review or endorsement.
## How to participate
- Learn how plugins are written in [plugin development](plugin-development.en.md).
+2
View File
@@ -36,6 +36,8 @@ DSH Desktop 是这套方式的第一个实践者:桌面壳本身就是一个
Fabric 的 capability 首先用于兼容判断、用户确认和审计,不会把同进程 JavaScript 伪装成安全沙箱。只有具备真实隔离证据的 Host 才能声称权限被技术强制执行。
市场目前仍处于[产品与安全设计阶段](../dsh-community-market/README.zh.md),尚未提供可用页面或安装器。目录收录只代表符合目录规则,不等于安全审核或推荐。
## 如何参与
- 在[插件开发](plugin-development.md)中了解插件如何编写。
+21
View File
@@ -0,0 +1,21 @@
MIT License
Copyright (c) 2026 Anywhere Labs
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
+4
View File
@@ -0,0 +1,4 @@
# Bilingual-pair consistency record. Both languages carry equal authority.
# Update both files and record their Git blob hashes after editing either side.
README.md: 84c07dbf671d4c76e6614ceecc6f04e9105d2936
README.zh.md: 0eaf527dfd9a480571a1766941fb6c77862f2de5
+56
View File
@@ -0,0 +1,56 @@
# DSH Community Market
[中文说明](README.zh.md)
DSH Community Market is the planned plugin-market shell for [DSH Desktop](../README.en.md). It will help people discover community plugins, understand what they do, and install them into the active work profile through one clear, confirmed action.
> **Current status: documentation-first scaffold.** This workspace does not yet contain a market page, catalog client, or installer. It is private in the monorepo until the first usable implementation is ready. Do not add it to a DSH profile yet.
## What we are building
The first usable version should make a small, understandable journey possible:
1. Browse and search a community catalog.
2. Open a plugin page with its description, source repository, and trust warning.
3. Choose **Install** and confirm the exact plugin and active profile.
4. Let Desktop run the existing managed DSH plugin command.
5. Prompt the user to restart Desktop when the profile change is complete.
The market is a shell around existing DSH capabilities. It does not invent a second plugin format, package manager, profile store, or privileged installer.
## Catalog source
The initial catalog adapter is planned around the public registry published by [DSH 1024Store](https://github.com/imsai-sh/awesome-deepseek-harness-plugins). That project maintains its own discovery, validation, website, API, and the separately published `dsh-1024store` plugin. DSH Community Market is an independent Desktop-specific shell; it is not a fork, repackaging, or official client of that plugin, and does not represent its maintainers, DeepSeek, or the listed plugin authors.
Catalog data is remote, replaceable, and untrusted. A listing means that a project matched the catalog's metadata rules; it does **not** mean that Anywhere Labs reviewed, recommends, or guarantees the plugin.
## Safety promise
- Background browsing never installs a package or executes repository code.
- Installation starts only after an explicit user action and confirmation.
- The market will derive an install target from a validated repository identity; it will never execute a command string returned by a catalog.
- The confirmation will show the exact source and active profile.
- Plugin changes will use the existing Desktop-managed DSH plugin service and run one operation at a time.
- The first release will not include accounts, telemetry, silent installs, automatic plugin updates, or a catalog backend.
Plugins run as local code with the user's permissions and may run package lifecycle scripts during installation. Read [Security](SECURITY.md) before implementing or reviewing installation behavior.
## Documentation
- [Market shell design](docs/market-shell.md): product boundary, architecture, profiles, failure behavior, and delivery phases.
- [Security](SECURITY.md): trust model, reporting, and non-negotiable installation rules.
- [Desktop plugin services](../dsh-plugin-desktop/docs/plugin-services.md): the existing `desktopProfiles` and `desktopPnpm` contracts the future implementation will consume.
- [DSH plugin development](../docs/plugin-development.en.md): the shared plugin model used by ordinary DSH and Desktop.
## Delivery plan
- **Phase 0 — current:** package ownership, documentation, trust boundary, and headless checks.
- **Phase 1:** read-only catalog provider, search, categories, plugin details, loading/empty/error states.
- **Phase 2:** explicit installation into the active profile through the managed Desktop service.
- **Later:** uninstall, update, recovery, richer verification signals, and multiple catalog providers.
Catalog collection, submission review, accounts, rankings, and hosting remain the responsibility of catalog providers rather than this package.
## License and attribution
Package code and documentation are licensed under the [MIT License](LICENSE). No DSH 1024Store code, artwork, or catalog snapshot is bundled in this scaffold. Its public catalog metadata is published under CC0-1.0; the source and provenance remain documented by the [upstream catalog project](https://github.com/imsai-sh/awesome-deepseek-harness-plugins).
+56
View File
@@ -0,0 +1,56 @@
# DSH Community Market
[English](README.md)
DSH Community Market 是为 [DSH Desktop](../README.md) 规划的插件市场壳。它将帮助用户发现社区插件、了解插件用途,并通过一次清晰的确认操作,把插件安装到当前正在使用的工作配置中。
> **当前状态:文档优先的初始化工程。** 这个 workspace 还没有市场页面、目录客户端或安装器,在首个可用实现完成前保持 monorepo 私有。现在不要把它加入 DSH profile。
## 我们要做什么
第一个可用版本只需要完成一条简单、容易理解的流程:
1. 浏览和搜索社区插件目录。
2. 打开插件详情,查看用途、源码仓库和安全提示。
3. 点击“安装”,确认准确的插件与当前工作配置。
4. 由 Desktop 调用已有的受管 DSH 插件命令。
5. 配置修改完成后,提示用户重启 Desktop。
市场只是现有 DSH 能力之上的产品壳,不会再发明一套插件格式、包管理器、profile 存储或高权限安装器。
## 目录来源
最初的目录适配器计划参考 [DSH 1024Store](https://github.com/imsai-sh/awesome-deepseek-harness-plugins) 发布的公开 registry。该项目独立维护插件发现、格式校验、网站、API,以及另行发布的 `dsh-1024store` 插件。DSH Community Market 是面向 Desktop 的独立市场壳,不是该插件的 fork、重新打包版本或官方客户端,也不代表其维护者、DeepSeek 或目录中的插件作者。
远程目录数据是可替换、且不可信的输入。一个项目被目录收录,只表示它符合目录的元数据规则;这**不表示** Anywhere Labs 已经审核、推荐或保证该插件。
## 安全承诺
- 后台浏览不会安装任何包,也不会执行仓库代码。
- 只有用户明确点击并确认后,安装才会开始。
- 市场会从经过校验的仓库身份推导安装目标,绝不执行目录返回的命令字符串。
- 确认框会展示准确来源和当前工作配置。
- 插件变更使用 Desktop 已有的受管 DSH 插件服务,并且一次只执行一个操作。
- 第一版不包含账号、遥测、静默安装、插件自动更新或自建目录后台。
插件会以用户权限作为本地代码运行,安装过程中还可能执行 package lifecycle script。实现或审核安装功能前,请先阅读[安全说明](SECURITY.zh.md)。
## 文档
- [市场壳设计](docs/market-shell.zh.md):产品边界、架构、profile、失败处理和交付阶段。
- [安全说明](SECURITY.zh.md):信任模型、漏洞反馈和不可妥协的安装规则。
- [Desktop 插件服务](../dsh-plugin-desktop/docs/plugin-services.zh.md):未来实现会使用的 `desktopProfiles` 与 `desktopPnpm` 合同。
- [DSH 插件开发](../docs/plugin-development.md):普通 DSH 与 Desktop 共用的插件模型。
## 交付计划
- **Phase 0 — 当前:** 确认包归属,写清产品与信任边界,建立 headless 检查。
- **Phase 1:** 只读目录 provider、搜索、分类、插件详情,以及加载、空白和错误状态。
- **Phase 2:** 通过 Desktop 受管服务,明确安装到当前 profile。
- **后续:** 卸载、更新、失败恢复、更丰富的验证信号和多个目录 provider。
目录采集、投稿审核、账号、排行榜和托管仍由目录 provider 负责,不属于这个 package。
## 许可证与来源说明
package 代码与文档遵循 [MIT License](LICENSE)。当前初始化工程没有打包 DSH 1024Store 的代码、素材或目录快照。它的公开目录元数据采用 CC0-1.0,具体来源与历史由[上游目录项目](https://github.com/imsai-sh/awesome-deepseek-harness-plugins)记录。
+4
View File
@@ -0,0 +1,4 @@
# Bilingual-pair consistency record. Both languages carry equal authority.
# Update both files and record their Git blob hashes after editing either side.
SECURITY.md: b7a733d0ee9981e620cf62f4a1d76faaeb84e610
SECURITY.zh.md: 6938e39e65c8a0cf22a367f987935c915f7c5b0c
+33
View File
@@ -0,0 +1,33 @@
# Security policy
[中文](SECURITY.zh.md)
## Current status
`dsh-community-market` is currently a private, documentation-only scaffold. It has no runtime entry, network request, user interface, or installer. There is no released functional version to add to a DSH profile.
## Trust model
Future catalog responses are untrusted remote input. A catalog listing is not a security review, compatibility promise, maintainer verification, or endorsement. Plugin repository links and display metadata must be validated and rendered as inert data.
Installing a plugin is a higher-risk action than browsing. A plugin runs locally with the user's permissions, and its package installation may execute lifecycle scripts. The future installer must therefore preserve all of these rules:
- installation starts only after an explicit user gesture and confirmation;
- the exact canonical source, derived install target, and active profile are visible before execution;
- no command string, script, or HTML from a catalog response is executed;
- Desktop installation goes through the managed `desktopPnpm.runPlugin()` capability;
- operations are cancellable, serialized, and joined during service teardown;
- credentials, environment variables, raw response bodies, and local paths are not exposed to the UI or logs;
- a catalog failure never blocks DSH or Desktop startup.
Any implementation that weakens these rules needs an explicit security review before merge.
## Reporting a vulnerability
Please report a suspected vulnerability privately to [t4wefan@qq.com](mailto:t4wefan@qq.com). Include the affected version or commit, operating system, reproduction steps, expected impact, and any proof of concept that can be shared safely.
Do not include secrets or personal data. Please do not open a public issue for an unpatched vulnerability. Ordinary bugs, catalog metadata corrections, and feature requests can use the repository's public issue tracker.
## Dependency and catalog reports
A vulnerability in a listed third-party plugin should normally be reported to that plugin's maintainer. A bad or misleading catalog entry should also be reported to the catalog provider. Report it here as well only when the market shell itself mishandles the entry or presents an unsafe action.
+33
View File
@@ -0,0 +1,33 @@
# 安全策略
[English](SECURITY.md)
## 当前状态
`dsh-community-market` 目前是 monorepo 内私有、且只有文档的初始化工程。它没有运行时入口、网络请求、用户界面或安装器,也没有可加入 DSH profile 的功能版本。
## 信任模型
未来的目录响应是不可信远程输入。被目录收录不等于经过安全审核,不代表兼容性承诺、维护者身份验证或推荐。插件仓库链接和展示信息必须经过校验,并且只能作为不可执行数据渲染。
安装插件的风险高于浏览。插件会以用户权限在本地运行,package 安装过程中还可能执行 lifecycle script。因此,未来安装器必须同时满足以下规则:
- 只有用户明确点击并确认后才开始安装;
- 执行前展示规范化来源、推导后的精确安装目标和当前 profile;
- 不执行目录响应中的命令字符串、脚本或 HTML;
- Desktop 安装只通过受管的 `desktopPnpm.runPlugin()` 能力;
- 操作可取消、串行执行,并在服务释放时等待完整退出;
- 不把凭据、环境变量、原始响应 body 或本地路径暴露给界面或日志;
- 目录故障不会阻止 DSH 或 Desktop 启动。
任何削弱这些规则的实现,都必须在合并前接受明确的安全审查。
## 报告安全问题
如果发现可能的安全问题,请通过 [t4wefan@qq.com](mailto:t4wefan@qq.com) 私下联系我们。请提供受影响的版本或 commit、操作系统、复现步骤、预期影响,以及可以安全分享的最小 proof of concept。
不要发送 secret 或个人数据;未修复漏洞也不要直接提交公开 issue。普通 bug、目录元数据修正和功能建议可以使用仓库的公开 issue tracker。
## 第三方插件与目录问题
目录中第三方插件的漏洞通常应先报告给插件维护者;错误或误导性的目录条目也应报告给目录 provider。只有市场壳本身错误处理该条目或展示了不安全操作时,才需要同时向本项目报告。
@@ -0,0 +1,4 @@
# Bilingual-pair consistency record. Both languages carry equal authority.
# Update both files and record their Git blob hashes after editing either side.
market-shell.md: b8ac564d2b5550c26b61c6158e91d47259ba9a54
market-shell.zh.md: add66a3de34f3da258afe8526ea413e4bbfbe16a
+152
View File
@@ -0,0 +1,152 @@
# DSH Community Market shell design
[中文](market-shell.zh.md)
Status: proposed; documentation scaffold only
This document defines the first implementation boundary for `dsh-community-market`. It is deliberately narrower than a complete marketplace. The package owns an in-product shell and adapters; it does not own the community catalog, package registry, or DSH profile format.
## Product goals
- Give users one calm place to discover, search, and understand community plugins.
- Keep catalog browsing read-only until a user explicitly chooses an action.
- Install only into the active profile, with the plugin source and profile visible before confirmation.
- Reuse existing DSH plugin and Desktop profile behavior instead of creating parallel state.
- Make the catalog provider replaceable, so the interface is not permanently coupled to one service.
- Keep the package useful without Electron-specific access. Desktop integrations are optional capabilities, not renderer globals.
## Non-goals for the first release
- Operating a catalog backend, GitHub crawler, submission queue, or moderation system.
- User accounts, payments, reviews, rankings, advertising, or telemetry.
- Claiming that a listed plugin is safe, reviewed, compatible, or endorsed.
- Silent install, automatic install, automatic plugin update, or background profile modification.
- Executing install commands, HTML, scripts, or links supplied by a catalog response.
- Editing inactive profiles or migrating plugins between profiles.
## Proposed boundary
```mermaid
flowchart LR
Catalog["Remote catalog provider"] --> Host["Market Host plugin<br/>fetch, limit, validate, normalize"]
Host --> Route["Ordinary DSH route or RPC"]
Route --> Client["Market client plugin<br/>search, details, confirmation"]
Profiles["desktopProfiles<br/>active profile"] --> Host
Pnpm["desktopPnpm<br/>managed plugin operation"] --> Host
Host -. "no Desktop services" .-> Browse["Read-only browsing remains available"]
```
The renderer receives normalized plain data through an ordinary DSH route or RPC. It does not receive Electron, filesystem, process, `desktopRuntime`, or package-manager access. The Host owns catalog I/O, validation, installation orchestration, cancellation, and operation serialization.
## Catalog provider
The first adapter is planned for the public registry endpoint documented by [DSH 1024Store](https://github.com/imsai-sh/awesome-deepseek-harness-plugins):
```text
GET https://deepseek1024.com/api/v1/registry
```
The endpoint and its schema belong to that independent project. They must stay behind a provider interface rather than becoming UI assumptions. A normalized snapshot needs only:
- source identity and source page;
- catalog update time;
- ordered categories with localized labels;
- plugin identity, name, owner, repository URL, category, and localized description;
- optional display metadata such as stars.
Remote fields are display data, not executable instructions. The provider must enforce an HTTPS endpoint, timeout, response-size limit, JSON content, a strict schema, unique identifiers, bounded strings, and canonical repository URLs. Unknown fields are ignored. Text is rendered as text, never as raw HTML.
The compact registry does not prove package ownership, security review, compatibility, or maintainer identity. The UI must always show the catalog source and a visible statement that listing is not endorsement.
## Read-only browsing
Phase 1 provides:
- loading, empty, offline, invalid-response, and retry states;
- local search over normalized names and descriptions;
- category filtering;
- a details view with the source repository and catalog attribution;
- an unavailable state when installation capability is absent.
Loading the catalog never invokes a package manager, resolves a local executable, modifies a profile, or records an installation event. Catalog errors do not stop DSH or Desktop from starting.
## Installation boundary
Installation belongs to Phase 2 and starts only from a user gesture. Before execution, the confirmation must show:
- plugin name;
- canonical source repository;
- exact derived install target;
- active profile name;
- a warning that plugins run locally with the user's permissions;
- a warning that package lifecycle scripts may run during installation.
The catalog's `install` field, documentation snippets, or arbitrary command strings are never executed. For the initial GitHub catalog, the Host derives the target from a validated `owner/repository[/sub/directory]` identity and produces the one supported GitHub dependency form. The derivation and quoting rules must be covered by tests before installation is enabled.
On Desktop, the initial adapter will use the public services already owned by `dsh-plugin-desktop`:
1. Read the active identity from `desktopProfiles.current`.
2. Invoke `desktopPnpm.runPlugin()` with an `add` operation, an explicit absolute invoking directory, and an `AbortSignal`.
3. Stream bounded progress to the UI without exposing environment variables or command internals.
4. Permit one mutation at a time.
5. Treat non-zero exit, signal, cancellation, service disposal, and profile restart as distinct outcomes.
6. On success, tell the user that Desktop must restart before the new plugin is loaded.
When Desktop services are unavailable, the first implementation stays read-only and explains why installation is disabled. It must not fall back to ambient `pnpm`, a shell command, or a guessed `dsh` executable. A future ordinary-DSH installer requires a supported Host capability with equivalent profile and cancellation semantics.
## Profile behavior
- The active profile is the only installation target.
- Installed-state queries are scoped to that profile.
- The confirmation repeats the profile name so the target is never implicit.
- Switching profiles remains owned by `desktopProfiles.select()` and takes effect through the existing controlled restart.
- The market never modifies an inactive profile in the background.
- A profile switch or service disposal cancels or joins any owned operation before the plugin generation ends.
Sessions and records are outside the market's responsibility. The market does not promise that arbitrary custom profiles share storage; it only reports and mutates plugin membership for the selected profile.
## Failure behavior
| Situation | User-visible result | Side effect |
| --- | --- | --- |
| Offline, timeout, non-200, oversized, or invalid catalog | Catalog unavailable with Retry | None |
| Unknown or unsafe repository identity | Installation disabled with reason | None |
| Desktop install capability missing | Browsing works; Install is unavailable | None |
| User cancels confirmation | Return to details | None |
| Installation is cancelled or fails | Bounded error summary and Retry | No second automatic attempt |
| Installation succeeds | Restart-required message | Active profile was reconciled by the managed service |
Raw response bodies, filesystem paths, tokens, environment variables, and command strings are never included in user-facing errors or telemetry.
## Delivery phases
### Phase 0: documentation scaffold
- Own the npm name and monorepo package boundary.
- Record catalog attribution, trust rules, and integration decisions.
- Keep the package private and non-loadable.
### Phase 1: read-only market shell
- Host and Client plugin entries.
- Replaceable catalog provider and strict normalization.
- Search, categories, details, and resilient state handling.
- Headless unit tests and Loader smoke; no installer.
### Phase 2: confirmed active-profile install
- Optional Desktop capability detection.
- Exact target derivation and two-step user intent.
- Managed, cancellable, serialized operation and restart guidance.
### Later work
- Installed-state detail, uninstall, update, and recovery.
- Multiple catalog providers and source selection.
- Stronger verification signals based on independently specified evidence.
## Attribution and independence
The design is informed by [imsai-sh/awesome-deepseek-harness-plugins](https://github.com/imsai-sh/awesome-deepseek-harness-plugins), also presented as DSH 1024Store. That project also publishes the separate `dsh-1024store` plugin. DSH Community Market is not a fork, repackaging, or official client of that plugin. Its application code is MIT licensed and its catalog metadata is CC0-1.0. This scaffold copies neither its code nor its artwork and bundles no catalog snapshot.
DSH Community Market is an independent Anywhere Labs project. Catalog inclusion does not imply endorsement by Anywhere Labs, DSH 1024Store, DeepSeek, or a plugin author.
@@ -0,0 +1,152 @@
# DSH Community Market 市场壳设计
[English](market-shell.md)
状态:设计提案;当前只有文档初始化工程
本文定义 `dsh-community-market` 第一阶段的实现边界。它刻意比完整的插件市场更小:package 只负责产品内的市场壳和适配器,不负责社区目录、包 registry 或 DSH profile 格式。
## 产品目标
- 给用户一个安静、清晰的入口,用来发现、搜索和了解社区插件。
- 在用户明确选择操作前,目录浏览始终保持只读。
- 只安装到当前 profile,并在确认前展示插件来源和目标 profile。
- 复用现有 DSH 插件与 Desktop profile 行为,不创建平行状态。
- 让目录 provider 可以替换,避免界面永久绑定某一个服务。
- 不依赖 Electron 私有访问也能工作;Desktop 集成是可选能力,不是 renderer 全局对象。
## 第一版不做什么
- 运营目录后台、GitHub 爬虫、投稿队列或审核系统。
- 账号、付费、评论、排行榜、广告或遥测。
- 宣称被收录插件安全、经过审核、兼容或得到推荐。
- 静默安装、自动安装、插件自动更新或后台修改 profile。
- 执行目录响应中的安装命令、HTML、脚本或链接。
- 修改未激活 profile,或在 profile 之间迁移插件。
## 规划边界
```mermaid
flowchart LR
Catalog["远程目录 provider"] --> Host["Market Host 插件<br/>请求、限流、校验、标准化"]
Host --> Route["普通 DSH route 或 RPC"]
Route --> Client["Market Client 插件<br/>搜索、详情、确认"]
Profiles["desktopProfiles<br/>当前 profile"] --> Host
Pnpm["desktopPnpm<br/>受管插件操作"] --> Host
Host -. "没有 Desktop 服务" .-> Browse["仍可只读浏览"]
```
renderer 只通过普通 DSH route 或 RPC 接收标准化纯数据,不会获得 Electron、文件系统、进程、`desktopRuntime` 或包管理器访问。Host 负责目录 I/O、校验、安装编排、取消和操作串行化。
## 目录 provider
第一个适配器计划接入 [DSH 1024Store](https://github.com/imsai-sh/awesome-deepseek-harness-plugins) 公开文档中的 registry 接口:
```text
GET https://deepseek1024.com/api/v1/registry
```
接口及其 schema 属于该独立项目,必须放在 provider 接口之后,不能变成 UI 的隐含假设。标准化快照只需要:
- 来源身份与来源页面;
- 目录更新时间;
- 带本地化名称和顺序的分类;
- 插件身份、名称、作者、仓库 URL、分类和本地化描述;
- stars 等可选展示信息。
远程字段只是展示数据,不是可执行指令。provider 必须限制为 HTTPS,设置超时和响应大小上限,校验 JSON 与严格 schema,保证 ID 唯一、字符串有界、仓库 URL 规范。未知字段直接忽略;文本只能按文本渲染,不能作为原始 HTML。
精简 registry 无法证明 package 所有权、安全审核、兼容性或维护者身份。界面必须始终展示目录来源,并明显说明“收录不等于推荐”。
## 只读浏览
Phase 1 提供:
- 加载、空目录、离线、非法响应和重试状态;
- 基于标准化名称与描述的本地搜索;
- 分类筛选;
- 包含源码仓库和目录来源的详情页;
- 缺少安装能力时的不可用说明。
加载目录时不会调用包管理器、解析本地 executable、修改 profile 或记录安装事件。目录错误也不会阻止 DSH 或 Desktop 启动。
## 安装边界
安装属于 Phase 2,并且只能由用户操作开始。执行前的确认必须展示:
- 插件名称;
- 规范化源码仓库;
- 精确推导出的安装目标;
- 当前 profile 名称;
- 插件会以用户权限在本地运行的提示;
- 安装时可能执行 package lifecycle script 的提示。
目录中的 `install` 字段、文档命令或任意命令字符串都不会被执行。对最初的 GitHub 目录,Host 会从经过校验的 `owner/repository[/sub/directory]` 身份推导唯一受支持的 GitHub dependency 形式。启用安装前,推导和引用规则必须由测试锁定。
在 Desktop 中,最初的适配器会使用 `dsh-plugin-desktop` 已提供的公开服务:
1. 从 `desktopProfiles.current` 读取当前身份。
2. 调用 `desktopPnpm.runPlugin()`,传入 `add` 操作、明确的绝对 invoking directory 和 `AbortSignal`。
3. 向界面输出有界进度,但不暴露环境变量或命令内部细节。
4. 同一时间只允许一个修改操作。
5. 区分非零退出、signal、取消、服务释放和 profile 重启。
6. 成功后明确提示用户:重启 Desktop 后新插件才会加载。
没有 Desktop 服务时,第一版仍可只读浏览,并说明为什么不能安装。它不会退回 ambient `pnpm`、shell 命令或猜测的 `dsh` executable。未来若支持普通 DSH 安装,必须先有同等 profile 与取消语义的正式 Host 能力。
## Profile 行为
- 当前 profile 是唯一安装目标。
- 已安装状态查询也按当前 profile 隔离。
- 确认框再次显示 profile 名称,目标不能隐含。
- 切换 profile 继续由 `desktopProfiles.select()` 管理,并通过已有的受控重启生效。
- 市场不会在后台修改未激活 profile。
- profile 切换或服务释放时,必须先取消或等待自己拥有的操作,再结束插件 generation。
会话和记录不属于市场职责。市场不会承诺任意自定义 profile 共享存储,只负责报告和修改选中 profile 的插件成员。
## 失败处理
| 情况 | 用户看到什么 | 副作用 |
| --- | --- | --- |
| 离线、超时、非 200、响应过大或格式非法 | 目录暂不可用,并提供重试 | 无 |
| 未知或不安全的仓库身份 | 禁用安装并说明原因 | 无 |
| 缺少 Desktop 安装能力 | 可以浏览,但安装不可用 | 无 |
| 用户取消确认 | 返回详情页 | 无 |
| 安装取消或失败 | 有界错误摘要和重试入口 | 不自动进行第二次尝试 |
| 安装成功 | 提示需要重启 | 当前 profile 已由受管服务完成 reconcile |
面向用户的错误或遥测中,不得包含原始响应 body、文件路径、token、环境变量或命令字符串。
## 交付阶段
### Phase 0:文档初始化工程
- 确认 npm 名称和 monorepo package 边界。
- 记录目录来源、信任规则和集成决策。
- package 保持私有且不可加载。
### Phase 1:只读市场壳
- Host 与 Client 插件入口。
- 可替换目录 provider 与严格标准化。
- 搜索、分类、详情和完整状态处理。
- headless 单元测试与 Loader smoke;不包含安装器。
### Phase 2:确认后安装到当前 profile
- 可选 Desktop 能力检测。
- 精确目标推导和两步用户意图。
- 受管、可取消、串行化的操作与重启说明。
### 后续工作
- 已安装状态详情、卸载、更新与失败恢复。
- 多个目录 provider 和来源选择。
- 基于独立规范证据的更强验证信号。
## 来源与独立性
本设计参考 [imsai-sh/awesome-deepseek-harness-plugins](https://github.com/imsai-sh/awesome-deepseek-harness-plugins),该项目也以 DSH 1024Store 展示,并另行发布 `dsh-1024store` 插件。DSH Community Market 不是该插件的 fork、重新打包版本或官方客户端。其应用代码使用 MIT,目录元数据使用 CC0-1.0。当前初始化工程没有复制其代码或素材,也没有打包目录快照。
DSH Community Market 是 Anywhere Labs 的独立项目。目录收录不表示 Anywhere Labs、DSH 1024Store、DeepSeek 或插件作者对项目作出推荐。
+45
View File
@@ -0,0 +1,45 @@
{
"name": "dsh-community-market",
"version": "0.1.0-dev.0",
"private": true,
"description": "Documentation-first shell for a community plugin market in DSH Desktop",
"license": "MIT",
"publishConfig": {
"access": "public",
"registry": "https://registry.npmjs.org"
},
"repository": {
"type": "git",
"url": "git+https://github.com/anywhere-labs/deepseek-harness-desktop.git",
"directory": "dsh-community-market"
},
"homepage": "https://github.com/anywhere-labs/deepseek-harness-desktop/tree/master/dsh-community-market#readme",
"bugs": {
"url": "https://github.com/anywhere-labs/deepseek-harness-desktop/issues"
},
"type": "module",
"files": [
"docs/**",
"LICENSE",
"README.md",
"README.zh.md",
"README.i18n.yaml",
"SECURITY.md",
"SECURITY.zh.md",
"SECURITY.i18n.yaml"
],
"engines": {
"node": "^22.19.0 || >=24.0.0"
},
"scripts": {
"check": "node scripts/verify-docs.mjs",
"prepack": "yarn run check"
},
"keywords": [
"deepseek",
"dsh",
"plugin",
"marketplace",
"community"
]
}
@@ -0,0 +1,79 @@
import { execFileSync } from 'node:child_process'
import { existsSync, readFileSync } from 'node:fs'
import { dirname, resolve } from 'node:path'
import { fileURLToPath } from 'node:url'
const packageRoot = dirname(dirname(fileURLToPath(import.meta.url)))
const fail = message => { throw new Error(`verify-market-docs: ${message}`) }
const read = path => readFileSync(resolve(packageRoot, path), 'utf8')
const manifest = JSON.parse(read('package.json'))
if (manifest.name !== 'dsh-community-market') fail('package name must remain dsh-community-market')
if (manifest.private !== true) fail('the documentation scaffold must stay private until a runtime exists')
for (const field of ['main', 'module', 'types', 'exports', 'bin', 'dsh', 'dependencies', 'optionalDependencies']) {
if (manifest[field] !== undefined) fail(`documentation scaffold must not declare ${field}`)
}
const publicFiles = [
'LICENSE',
'README.i18n.yaml',
'README.md',
'README.zh.md',
'SECURITY.i18n.yaml',
'SECURITY.md',
'SECURITY.zh.md',
'docs/market-shell.i18n.yaml',
'docs/market-shell.md',
'docs/market-shell.zh.md',
]
for (const path of [...publicFiles, 'scripts/verify-docs.mjs']) {
if (!existsSync(resolve(packageRoot, path))) fail(`${path} is missing`)
}
const expectedFiles = [
'docs/**',
'LICENSE',
'README.md',
'README.zh.md',
'README.i18n.yaml',
'SECURITY.md',
'SECURITY.zh.md',
'SECURITY.i18n.yaml',
]
if (JSON.stringify(manifest.files) !== JSON.stringify(expectedFiles)) {
fail('package files must contain only the reviewed documentation surface')
}
const pairs = [
['README.i18n.yaml', ['README.md', 'README.zh.md']],
['SECURITY.i18n.yaml', ['SECURITY.md', 'SECURITY.zh.md']],
['docs/market-shell.i18n.yaml', ['docs/market-shell.md', 'docs/market-shell.zh.md']],
]
for (const [recordPath, paths] of pairs) {
const lines = read(recordPath).split(/\r?\n/u)
for (const path of paths) {
const hash = execFileSync('git', ['hash-object', `--path=${path}`, path], {
cwd: packageRoot,
encoding: 'utf8',
stdio: ['ignore', 'pipe', 'pipe'],
}).trim()
const name = path.split('/').at(-1)
if (!lines.includes(`${name}: ${hash}`)) fail(`${recordPath} is stale for ${path}`)
}
}
const markdownFiles = publicFiles.filter(path => path.endsWith('.md'))
for (const path of markdownFiles) {
const source = read(path)
for (const match of source.matchAll(/\]\(([^)]+)\)/gu)) {
const target = match[1].trim().replace(/^<|>$/gu, '')
if (/^(?:https?:|mailto:|#)/u.test(target)) continue
const localPath = decodeURIComponent(target.split('#', 1)[0])
if (!localPath) continue
if (!existsSync(resolve(packageRoot, dirname(path), localPath))) {
fail(`${path} links to missing ${localPath}`)
}
}
}
process.stdout.write(`verify-market-docs: ${markdownFiles.length} Markdown files and 3 bilingual pairs are consistent\n`)
+3 -2
View File
@@ -10,7 +10,8 @@
},
"workspaces": [
"dsh-plugin-desktop",
"dsh-community-fabric"
"dsh-community-fabric",
"dsh-community-market"
],
"resolutions": {
"app-builder-lib@npm:26.15.3": "patch:app-builder-lib@npm%3A26.15.3#./patches/app-builder-lib@26.15.3.patch",
@@ -49,7 +50,7 @@
"typecheck": "yarn workspace dsh-plugin-desktop typecheck",
"test": "yarn workspace dsh-plugin-desktop test",
"check:layout": "node scripts/verify-layout.mjs",
"check": "yarn check:layout && yarn workspace dsh-community-fabric check && yarn workspace dsh-plugin-desktop check",
"check": "yarn check:layout && yarn workspace dsh-community-fabric check && yarn workspace dsh-community-market check && yarn workspace dsh-plugin-desktop check",
"dev": "yarn workspace dsh-plugin-desktop dev",
"start": "yarn workspace dsh-plugin-desktop start",
"package:dir": "yarn workspace dsh-plugin-desktop package:dir",
+21 -4
View File
@@ -15,6 +15,7 @@ const workspace = readJson('package.json')
const upstream = readJson('upstream.json')
const plugin = readJson('dsh-plugin-desktop/package.json')
const fabric = readJson('dsh-community-fabric/package.json')
const market = readJson('dsh-community-market/package.json')
const upstreamPackage = readJson('deepseek-harness/package.json')
const noteDirectory = '.agents/notes/implemented/process'
const noteName = '2026-08-15-pinned-upstream-and-isolated-yarn-workspace'
@@ -24,13 +25,22 @@ const noteRecordPath = `${noteDirectory}/${noteName}.i18n.yaml`
if (workspace.packageManager !== 'yarn@4.18.0') {
fail('the product workspace must pin yarn@4.18.0')
}
if (JSON.stringify(workspace.workspaces) !== JSON.stringify(['dsh-plugin-desktop', 'dsh-community-fabric'])) {
fail('the root Yarn workspace must contain the desktop and community-fabric packages')
if (JSON.stringify(workspace.workspaces) !== JSON.stringify([
'dsh-plugin-desktop',
'dsh-community-fabric',
'dsh-community-market',
])) {
fail('the root Yarn workspace must contain the desktop, community-fabric, and community-market packages')
}
for (const [name, manifest] of [['dsh-plugin-desktop', plugin], ['dsh-community-fabric', fabric]]) {
for (const [name, manifest] of [
['dsh-plugin-desktop', plugin],
['dsh-community-fabric', fabric],
['dsh-community-market', market],
]) {
if (manifest.packageManager !== undefined) fail(`${name} must inherit the root Yarn release`)
}
if (fabric.name !== 'dsh-community-fabric') fail('the Fabric workspace must own dsh-community-fabric')
if (market.name !== 'dsh-community-market') fail('the market workspace must own dsh-community-market')
const claudePath = resolve(root, 'CLAUDE.md')
const claudeStat = lstatSync(claudePath)
// Windows checkouts materialize the symlink as a regular file holding the
@@ -48,6 +58,8 @@ for (const legacyFile of [
'dsh-plugin-desktop/pnpm-workspace.yaml',
'dsh-community-fabric/pnpm-lock.yaml',
'dsh-community-fabric/pnpm-workspace.yaml',
'dsh-community-market/pnpm-lock.yaml',
'dsh-community-market/pnpm-workspace.yaml',
]) {
if (existsSync(resolve(root, legacyFile))) fail(`${legacyFile} must not exist`)
}
@@ -61,7 +73,12 @@ if (typeof upstreamPackage.packageManager !== 'string' || !upstreamPackage.packa
fail('the upstream checkout must retain its pnpm package manager')
}
for (const [owner, manifest] of [['root', workspace], ['desktop', plugin], ['fabric', fabric]]) {
for (const [owner, manifest] of [
['root', workspace],
['desktop', plugin],
['fabric', fabric],
['market', market],
]) {
for (const field of ['dependencies', 'devDependencies', 'optionalDependencies', 'peerDependencies', 'resolutions']) {
for (const [name, range] of Object.entries(manifest[field] ?? {})) {
if (typeof range !== 'string') continue
+6
View File
@@ -6637,6 +6637,12 @@ __metadata:
languageName: unknown
linkType: soft
"dsh-community-market@workspace:dsh-community-market":
version: 0.0.0-use.local
resolution: "dsh-community-market@workspace:dsh-community-market"
languageName: unknown
linkType: soft
"dsh-plugin-desktop@workspace:dsh-plugin-desktop":
version: 0.0.0-use.local
resolution: "dsh-plugin-desktop@workspace:dsh-plugin-desktop"