aryswisnu/dsh-composition-check

A local CLI that checks an ordered DSH profile bundle stack for simple Cordis patch ownership conflicts. It reports duplicate inserted entry IDs as errors and later { id: ... } patches that target an earlier entry as override warnings, and it is careful about what its findings mean: proven static means only that the listed local patch does — so a finding is reported with its confidence rather than as certainty. --json mode makes stdout JSON-only for scripting, and --runtime adds a real install-and-dump check in a throwaway DSH home.

Other ★ 0 updated 2026-08-14 ✅ runtime-tested
View on GitHub ↗

Install

npm install --save-dev dsh-composition-check

README Install block quoted verbatim (it also lists npm install -g dsh-composition-check). The README states plainly that this is an ordinary npm CLI package, NOT a DSH bundle, so it is not added with dsh plugin add — it is run against a stack file with npx dsh-composition-check stack.yml. Registry check 2026-09-16: dsh-composition-check returned 404 on npm, so no version is asserted; verify the package name before relying on it.

Compatibility

README: a bundle in the stack file must contain a package.json declaring dsh.bundle.patch (accepted as dsh.bundle.patch or as nested JSON fields) plus the declared cordis.patch.yml in that bundle directory. Default mode is static-only and never invokes DSH; --runtime creates a temporary DSH_HOME, runs dsh plugin --profile <p> add <bundle> for each ordered layer and then dsh --profile <p> --dump-config, removing the temporary home in finally and never deliberately modifying your existing DSH_HOME. Exit status is 0 for no errors, 1 for checker/runtime errors and 2 for usage or malformed input.

Details

Recent updates

The README documents the modes, the stack-file format and the confidence semantics rather than a release-by-release table.

FAQ

Do I add it with dsh plugin add?
No — the README says it is an ordinary npm CLI package, not a DSH bundle. Install it with npm install --save-dev dsh-composition-check and run npx dsh-composition-check stack.yml.
Will it touch my existing DSH home?
The README says the default mode is static-only and never invokes DSH, and that --runtime creates a temporary DSH_HOME and removes it in finally.
What counts as an error versus a warning?
Per the README, duplicate inserted entry IDs are errors and a later { id: ... } patch targeting an earlier entry is an override warning; exit status 0/1/2 signals clean, checker-or-runtime error, or usage/malformed input.

More plugins in Other

Browse more in Other

Guides for Other plugins