MicroMilo/upstream-radar
Always-on vulnerability and breaking-change impact monitoring for DeepSeek Harness plugins.
Always-on compatibility testing for DeepSeek Harness plugins across headless, Web and TUI, built for the DSH plugin ecosystem. It binds exact plugin bytes to an exact DSH host and runtime, lets an agent derive a bounded environment from repository instructions and prior evidence, then proves the relationship in disposable GitHub VMs — re-running when the ecosystem changes or when evidence expires, so it tests the current version rather than only a diff. It targets the gaps that separate a green source repository from an installable package: a README advertising a version that was never published, a plugin importing a newer DSH package than its peer range allows, package.json and the lockfile describing different releases, an install-time build needing tools the user lacks, or a missing DSH host dependency that leaves the graph incomplete. It builds one versioned evidence ledger with a reverse impact index and turns attributable failures into fixable maintainer reports. The README is explicit that a static review is evidence about a package and an isolated runtime review is evidence about one exact plugin × DSH × Node/profile pair — neither is a timeless compatibility badge or a security certificate.
Install
npx --yes upstream-radar@0.45.0 scan https://github.com/owner/dsh-plugin --fail-on neverREADME "Try a real check": no local DSH profile is needed to review one exact published artifact without executing plugin code — npx --yes upstream-radar@0.45.0 inspect <pkg>@<version> --deep --fail-on never for a package, or the scan form above for a public repository (it reads source manifests, DSH metadata and lockfiles without installing dependencies, running lifecycle scripts, loading the plugin, starting DSH or calling an LLM). Maintained GitHub Actions workflows in examples/github-actions/ can be copied into a repository to run the checks on every change. npm upstream-radar 0.45.0 verified 2026-09-12 (registry repository field → github.com/MicroMilo/upstream-radar). Apache-2.0.
Compatibility
Runs from Node/npx. No local DSH profile or DSH install is required for the inspect and scan checks. Proof runs execute in disposable, secret-free GitHub VMs across three planes: headless load, Chromium Web boot, and a real PTY TUI interaction.
Details
- Repo: MicroMilo/upstream-radar
- Category: Infrastructure & Deployment
- Stars: 5
- Version: 0.45.0 (npm upstream-radar; registry repository field → github.com/MicroMilo/upstream-radar, verified 2026-09-12)
- Last push: 2026-09-21
- First seen: 2026-08-14
Recent updates
The README documents the pipeline as four steps (build one exact IR, derive a bounded install plan, prove each execution plane in fresh secret-free runners, keep the result alive on change or evidence expiry), the decision gate that separates plugin-attributable failures from detector gaps that must be held and calibrated, and the rule that missing evidence can never become a pass. It also lists the curated lists that index the project (awesome-dsh-plugin, awesome-deepseek-harness, awesome-deepseek-harness-plugins).
FAQ
- Do I need a DSH install to run a check?
- No. The README's first check reviews one exact published artifact (or a public repository with scan) without a local DSH profile and without executing plugin code — it reads manifests, DSH metadata and lockfiles only.
- Does a review prove a plugin is safe?
- No. The README states a static review is evidence about a package and an isolated runtime review is evidence about one exact plugin × DSH × Node/profile pair; neither is presented as a timeless compatibility badge or a security certificate.
- How does it stay current?
- Records are retested when DSH, the plugin or a dependency changes, or when the evidence expires — so it tests the current version rather than only the diff. Confirmed failures become fixable maintainer reports and clean retests close the loop.