aryswisnu/dsh-composition-check
A local CLI that checks an ordered DSH profile bundle stack for simple Cordis patch ownership conflicts. It reports duplicate inserted entry IDs as errors and later { id: ... } patches that target an earlier entry as override warnings, and it is careful about what its findings mean: proven static means only that the listed local patch does — so a finding is reported with its confidence rather than as certainty. --json mode makes stdout JSON-only for scripting, and --runtime adds a real install-and-dump check in a throwaway DSH home.
Install
npm install --save-dev dsh-composition-checkREADME Install block quoted verbatim (it also lists npm install -g dsh-composition-check). The README states plainly that this is an ordinary npm CLI package, NOT a DSH bundle, so it is not added with dsh plugin add — it is run against a stack file with npx dsh-composition-check stack.yml. Registry check 2026-09-16: dsh-composition-check returned 404 on npm, so no version is asserted; verify the package name before relying on it.
Compatibility
README: a bundle in the stack file must contain a package.json declaring dsh.bundle.patch (accepted as dsh.bundle.patch or as nested JSON fields) plus the declared cordis.patch.yml in that bundle directory. Default mode is static-only and never invokes DSH; --runtime creates a temporary DSH_HOME, runs dsh plugin --profile <p> add <bundle> for each ordered layer and then dsh --profile <p> --dump-config, removing the temporary home in finally and never deliberately modifying your existing DSH_HOME. Exit status is 0 for no errors, 1 for checker/runtime errors and 2 for usage or malformed input.
Details
- Repo: aryswisnu/dsh-composition-check
- Category: Other
- Stars: 0
- Version: npm CLI (name did not resolve on the registry when checked 2026-09-16; no version asserted)
- Last push: 2026-08-14
- First seen: 2026-08-14
Recent updates
The README documents the modes, the stack-file format and the confidence semantics rather than a release-by-release table.
FAQ
- Do I add it with dsh plugin add?
- No — the README says it is an ordinary npm CLI package, not a DSH bundle. Install it with npm install --save-dev dsh-composition-check and run npx dsh-composition-check stack.yml.
- Will it touch my existing DSH home?
- The README says the default mode is static-only and never invokes DSH, and that --runtime creates a temporary DSH_HOME and removes it in finally.
- What counts as an error versus a warning?
- Per the README, duplicate inserted entry IDs are errors and a later { id: ... } patch targeting an earlier entry is an override warning; exit status 0/1/2 signals clean, checker-or-runtime error, or usage/malformed input.