Skip to content
dsh-market Browse plugins GitHub 中文

MicroMilo/upstream-radar

Watches DSH and plugin releases, retests exact published artifacts in disposable runners, publishes machine-readable compatibility evidence, and reconciles managed issues after fixes.

Stars ★ 12 Category Security & Permissions Listed 2026-08-15 npm upstream-radar

Install

Inside DeepSeek Harness, with dsh-market

dsh plugin --profile web add dshmarket

Or from the command line

dsh plugin --profile web add upstream-radar

Installing runs third-party code with your own permissions — it can read your files, use your credentials and reach the network. Review the source first, and pin a commit (github:owner/repo#sha) when you can.

README

Upstream Radar watches exact DSH and plugin releases, persists every affected case, and wakes an Agent only when the input changes. The Agent reads the repository, chooses evidence-backed Node.js and execution profiles, installs and runs the exact artifacts in disposable CI, watches them while they run, and publishes a reviewable compatibility report.

No guessed matrix. No “install succeeded, therefore compatible.” No silent unknowns.

What you get

  • Change-driven analysis — a DSH release fans out to your plugin cohort; a plugin release analyzes only that plugin.
  • Agent-owned environment discovery — README, manifests, lockfiles, CI, and startup scripts determine Node.js, package manager, and profile selection.
  • Active runtime supervision — the Agent reads incremental logs, inspects running processes, handles recoverable build gates, adjusts, and retries.
  • Exact, durable evidence — every report is bound to plugin bytes, source commit, DSH version, Node.js version, profile, commands, and logs.
  • Safe retries and deduplication — interrupted executor work stays pending; an unchanged completed input does not run twice.

The loop

flowchart LR
  Change["Schedule or upstream change"] --> Task["Persist exact task"]
  Task --> Agent["Agent reviews repository evidence"]
  Agent --> Run["Install, run, watch, recover"]
  Run --> Report["Versioned report and logs"]
  Report --> State["Deduplicate or retry"]
  State --> Change

The model recommends and operates within a bounded tool contract. Deterministic code selects exact versions, verifies artifacts, isolates execution, and decides whether evidence is complete. Plugin code never receives model credentials or repository write tokens.

See it working

Reports preserve compatible, incompatible, unknown, and externally blocked outcomes separately. Missing credentials, missing coverage, and executor faults cannot become a pass.

Try it in 30 seconds

Inspect one exact published artifact without executing plugin code:

npx --yes upstream-radar@0.45.0 inspect \
  @sanqi-normal/dsh-webui-market-plugin@0.5.4 \
  --deep --fail-on never

Or review a public plugin repository without installing it:

npx --yes upstream-radar@0.45.0 scan \
  https://github.com/owner/dsh-plugin \
  --fail-on never

The static commands read bounded package and repository evidence. They do not install dependencies, execute lifecycle scripts, start DSH, or call an LLM.

Automate the compatibility loop

Start from one maintained workflow:

This repository's deployed loop runs from upstream-observer.yml. Its single operator entry point is examples/dsh/active-agent/policy.json:

{
  "schema": "upstream-radar.dsh-active-agent-policy/v1alpha1",
  "dsh": { "channel": "next" },
  "defaults": {},
  "plugins": [
    { "targetId": "context" },
    { "targetId": "dsh-tui" }
  ]
}

Leave Node.js and profiles unset to let the Agent infer them. Override them globally or per plugin when you need a fixed experiment. Exact DSH or plugin versions require a matching sourceRef, so repository evidence cannot drift from installed bytes. See the policy reference.

What a result means

Result Meaning
compatible The exact tested cell completed its required install and runtime checks.
incompatible Reproducible evidence failed a required compatibility boundary.
unknown Execution happened, but coverage or attribution was insufficient.
blocked An external account, credential, source, or executor prevented completion.

Results are scoped observations, not permanent compatibility badges or security certificates. A new artifact, source commit, DSH release, runtime policy, or expired evidence creates a new input.

Built for

  • Plugin authors who want release failures caught before users report them.
  • DSH ecosystem maintainers who need one comparable, auditable evidence feed.
  • Platform teams that need repeatable upgrade decisions instead of a manual README-and-log investigation.

Upstream Radar is listed by awesome-dsh-plugin, awesome-deepseek-harness, and awesome-deepseek-harness-plugins.

Content from the project README on GitHub ↗

Comments

Comments live in GitHub Discussions. Sign in with GitHub to post or react.