dsh-permission-rules
CheckedCurrentv0.4.1Sandbox
Declarative Claude Code-style permission rules for DeepSeek Harness: ordered allow/deny/ask rules with tool-name, argument (glob/regex), and workspace-path matching on the tools/pre-execute waterfall, full session-log audit, and HMR rule reload.
Install
dsh plugin --profile web add dsh-permission-rulesSwap web for your own profile name. First use initializes the profile for you.
Checks
- declares-bundleDeclares dsh.bundle.patch → cordis.patch.yml
- patch-shippedThe patch file ships in the tarball
- patch-parsesPatch parses and mounts 1 plugin row(s)
- rows-resolvableEvery plugin row resolves to a published package
- entry-shippedEntry module ships: lib/index.js
- prebuiltPrebuilt — installs without running build scripts
What it mounts
insertpermission-rulesdsh-permission-rules
rulesFilebadFilePolicymaxRulespatternModewatch
These are the rows the plugin's cordis.patch.yml inserts into your config tree. After installing, dsh --profile <name> --dump-config prints them back.
Version compatibility
@deepseek-ai/cordis^4.0.1→ 4.0.1Current
@deepseek-ai/dsh-llm0.1.0-rc.6→ 0.1.0-rc.6Current
@deepseek-ai/dsh-agent0.1.0-rc.6→ 0.1.0-rc.6Current
@deepseek-ai/dsh-tools0.1.0-rc.6→ 0.1.0-rc.6Current
@deepseek-ai/dsh-session0.1.0-rc.6→ 0.1.0-rc.6Current
@deepseek-ai/schemastery^3.18.0→ 3.18.1Current
@deepseek-ai/dsh-commands0.1.0-rc.6→ 0.1.0-rc.6Current
dsh moved 0.0.1-rc.1 to 0.1.0-rc.6 in three days. Note the dsh library packages promote current releases on the next tag; latest still points at the first-day version.