dsh-sast
Verified@tangxiaofeng7/dsh-sast · v0.1.0-rc.5 · MIT · Web UI
DSH 白盒审计模式:AI 驱动的 SAST,记录方法论、审计链路、漏洞与代码资产,并在 Web 中可视化展示。
Install
dsh plugin add @tangxiaofeng7/dsh-sast Confirm the layer applied with dsh --profile default --dump-config — see the install guide.
Source
Tags
Creators
Readme
dsh-sast — DSH 白盒审计模式
面向 DeepSeek Harness(dsh)的白盒代码审计模式: 输入代码仓库与用户/团队的审计方法论,记录审计意图、代码事实、污点链路、漏洞与代码资产, 并在 Web 中以审计链路、漏洞、代码资产、任务与进度、报告等视图展示。
安装
最快体验方式
npx --yes --legacy-peer-deps @tangxiaofeng7/dsh-sast
说明:
- npm 包名是 scoped 的
@tangxiaofeng7/dsh-sast(npx对只有单一 bin 的包会直接运行它); - 本包以精确版本声明 dsh 宿主的 peer 依赖(见
bundle.spec.ts契约),独立安装时 npm 会因 上游 peer 网络无法自动调和而报 ERESOLVE,因此 quick-start 需要携带--legacy-peer-deps; 在 dsh 宿主内正常组合安装时不受影响。
手工安装(同一条路径)
从 Release URL 安装
dsh plugin --profile web add https://github.com/tangxiaofeng7/dsh-sast/releases/latest/download/dsh-sast.tar.gz
重启 dsh 后,在新会话中选择自动注册的「白盒审计模式」。