dsh-market
已验证@thewaifu/dsh-market · v1.1.2 · Apache-2.0 · Web 界面
The dshmarket.ai plugin marketplace inside DeepSeek Harness Web Settings
安装
dsh plugin add @thewaifu/dsh-market 用 dsh --profile default --dump-config 确认 layer 已生效 —— 参见安装指南。
源码
发布到 npm 但没有公开仓库。安装前请检查包内容。
标签
说明文档
dsh-market
@thewaifu/dsh-market brings the dshmarket.ai plugin directory into the DeepSeek Harness WebUI. It adds a dedicated Plugin Market page under Settings, where users can discover, search, install, update, and uninstall plugins for the active web profile.
The market is a native DSH settings section, not an embedded remote website. Its catalog is read from dshmarket.ai, validated by the local Host, and rendered by the local plugin client.
Features
- Dedicated Settings > Plugin Market navigation entry with the native DSH Plugins icon.
- Live catalog sourced from
https://dshmarket.ai/plugins/. - Search by plugin name, package name, publisher, description, or capability.
- Filter by category, installed state, and available updates.
- Install, update, and uninstall actions for the DSH
webprofile. - Exact package versions and per-operation registry selection from the validated market catalog.
- Serialized profile mutations so two package operations cannot modify the profile concurrently.
- Automatic
package.jsonbackup before every profile mutation. - In-memory catalog caching with a bundled offline snapshot as the final fallback.
- English and Chinese user interfaces.
Requirements
- DeepSeek Harness with the WebUI installed and working.
- Node.js
^22.19.0or>=24.0.0. - A graphical browser that can open the local DSH WebUI.
- Network access to
https://dshmarket.ai/for live catalog updates. - Network access to npmjs.org or the registry selected by an individual catalog entry when installing plugins.
The bundled snapshot keeps the market browsable when the live catalog is temporarily unavailable, but installing a package still requires access to its package registry.
Install
Stop any running DSH WebUI, then add the package to the web profile:
dsh plugin --profile web add @thewaifu/dsh-market
If you run DSH through npm instead of a global dsh command, use:
npx @deepseek-ai/dsh plugin --profile web add @thewaifu/dsh-market
Start the WebUI:
dsh web
Open the address printed by DSH, select Settings, then select Plugin Market in the settings navigation.
Use the Plugin Market
The page loads the latest catalog automatically. Use the search box and filters to narrow the result list.
- Install adds the catalog's exact package version to the
webprofile. - Update is available only when the catalog version is newer than the installed version.
- Uninstall removes the package from the
webprofile. - Refresh bypasses the in-memory catalog cache and requests the current directory again.
- Cancel stops a queued or running market operation when cancellation is still possible.
Every install, update, or uninstall action requires confirmation. After a successful package change, stop and restart dsh web; an already running Host does not hot-reload profile packages from disk.
The market cannot update or uninstall itself from its own page. Manage @thewaifu/dsh-market with the DSH CLI commands below.
Update
Stop the WebUI, then run:
dsh plugin --profile web update @thewaifu/dsh-market
dsh web
If the installed DSH release does not provide the update operation, reinstalling with add updates the package:
dsh plugin --profile web add @thewaifu/dsh-market
dsh web
Uninstall
Stop the WebUI, then run:
dsh plugin --profile web remove @thewaifu/dsh-market
dsh web
Uninstalling the plugin does not remove its profile manifest backups under:
~/.dsh/profiles/web/.dsh-market/backups/
Migrate from the Former Local Package Name
Development builds previously used @thewaifu/waifu-plugin. Do not install both package names in the same profile because they register the same settings page. Stop the WebUI and replace the old package:
dsh plugin --profile web remove @thewaifu/waifu-plugin
dsh plugin --profile web add @thewaifu/dsh-market
dsh web
Catalog Updates
The Host reads the current dshmarket.ai plugin page and its same-origin Next.js data, then accepts only plugin records that pass strict field validation. Updating the plugin list on dshmarket.ai updates the live market without requiring a new @thewaifu/dsh-market release.
If the live request fails, the Host first uses its last valid in-memory response and then falls back to the snapshot bundled with this package. A new package release is needed only when the plugin implementation or its offline snapshot must change.
Security Model
- The remote catalog is treated as data. Remote JavaScript is not executed by the plugin.
- Browser mutation requests must be same-origin with the local DSH WebUI.
- Browser requests cannot supply arbitrary commands, filesystem paths, registries, or package versions.
- Package names and versions must match a validated market entry.
- Updates cannot downgrade or reinstall the same version.
- Package operations run one at a time in a strict FIFO queue.
- The Web profile manifest is backed up before every package mutation.
- A marketplace listing is not a security audit. Review a plugin before installing it because npm packages can execute local code through declared lifecycle scripts.
Troubleshooting
Plugin Market is missing from Settings
Confirm that the package is installed in the web profile:
dsh plugin --profile web list
The output must contain @thewaifu/dsh-market. Stop and restart the WebUI after installing or updating the package. If the browser still shows an old client bundle, perform a hard refresh.
The live catalog does not load
Confirm that https://dshmarket.ai/plugins/ is reachable from the computer running the DSH Host. The page may temporarily show cached or bundled snapshot data while the live source is unavailable.
An install, update, or uninstall fails
Read the operation output shown in Plugin Market. Confirm that:
- the DSH Host can write to its
webprofile; - the package registry is reachable;
- the requested package still exists at the catalog version; and
- no external package manager is changing the same profile at the same time.
Restart DSH after repairing the issue and retry the operation.
Install from Source
Production users should install the published npm package. For local development:
cd /path/to/dsh-market
pnpm --ignore-workspace install
pnpm run build
dsh plugin --profile web add "$(pwd)"
dsh web
Development Verification
pnpm --ignore-workspace install
pnpm run snapshot
pnpm run typecheck
pnpm run test
pnpm run build
pnpm run verify
npm pack
Publishing to npmjs.org
Maintainers must use an npm account that belongs to the @thewaifu organization and has permission to create public packages.
npm login --registry=https://registry.npmjs.org/
npm whoami --registry=https://registry.npmjs.org/
npm pack --pack-destination artifacts/npm
npm publish artifacts/npm/thewaifu-dsh-market-1.1.2.tgz --access public --tag latest --registry=https://registry.npmjs.org/
npm view @thewaifu/dsh-market version dist-tags --registry=https://registry.npmjs.org/
Never reuse a version that has already been published. Increment package.json before producing the next release tarball.
License
Licensed under the Apache License 2.0.