Install
Inside DeepSeek Harness, with dsh-market
dsh plugin --profile web add dshmarket
Or from the command line
dsh plugin --profile web add dsh-version-badge
Installing runs third-party code with your own permissions — it can read your files, use your credentials and reach the network. Review the source first, and pin a commit (github:owner/repo#sha) when you can.
README
A DSH (DeepSeek Harness) version badge that sits above the sidebar settings button. It always shows the current dsh version and lets you expand to see every core package version (CLI / base / web-app / web-frontend / agent). A Check for updates button beside it queries npm and offers one-click deploy when a newer build is out.
Features
- 🏷️ Persistent badge — above the sidebar settings button (part of the layout, not a floating widget), showing
DSH v<major-version> - 📋 Click to expand — lists each
@deepseek-aicore package version; click outside or ✕ to close - 🔄 Check for updates — queries the npm registry and compares against the latest (60s cache)
- 🚀 One-click deploy — upgrades the global dsh CLI (
@deepseek-ai/dsh@latest) and auto-restarts from a detached process - 🔒 Security model — write operations only accept same-origin loopback requests (loopback address + Origin matches Host + rejects forwarding headers)
- ⚡ Zero dependencies — plain host plugin with inline script injection (same mechanism as dsh-whale-widget), no client build
Install
dsh plugin --profile web add dsh-version-badge
Restart dsh web and refresh the browser; the badge appears above the settings button.
Configure (optional)
One-click deploy is enabled by default. To disable it (e.g. when the dsh process is managed by a supervisor), add to the profile's cordis.patch.yml:
- id: dsh-version-badge
name: dsh-version-badge
config:
allowRestart: false
The update panel then notes that deploy is disabled.
Uninstall
dsh plugin --profile web remove dsh-version-badge
Verify
curl http://127.0.0.1:3080/dsh-version/version.json
curl http://127.0.0.1:3080/dsh-version/check-update.json
curl http://127.0.0.1:3080/dsh-version/widget.js
Deploy status (if any):
curl http://127.0.0.1:3080/dsh-version/deploy-status.json
Security notes
- Read-only endpoints (
version.json/check-update.json/deploy-status.json): loopback address + no forwarding headers; if an Origin is present it must match Host - Write endpoint (
deploy-update.jsonPOST): loopback address + no forwarding headers + Origin must be present and match Host (rejects curl / cross-site, Origin-less requests) - Deploy always uses the npm dist-tag
latest; any client-supplied tag/version is ignored - The deploy result is written to
$DSH_HOME/dsh-update-deploy.result.txtand queryable via the status endpoint; if npm fails the current version stays unchanged
Structure
dsh-version-badge/
├── package.json # DSH bundle plugin metadata
├── README.md # this file (Chinese)
├── README.en.md # English version
├── cordis.patch.yml # plugin mount declaration
└── lib/
└── index.js # host plugin body (with inline browser script)
License
MIT
Comments
Comments live in GitHub Discussions. Sign in with GitHub to post or react.