npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@elinpf/dsh-ops-tool-ssh

v0.4.1

Published

ssh tool consumer of the ops-access seam — resolves ssh profiles and runs commands via ctx.shell, injecting credential paths automatically.

Readme

@elinpf/dsh-ops-tool-ssh

DeepSeek Harness 运维模式的 ssh 工具 — 使用已注册的 ssh 访问档案在远程主机上执行命令(凭证、端口、user@host 自动注入)。支持密钥登录和密码登录(经 sshpass)。

功能

ops-access 凭据缝隙的消费方:模型用档案名加命令调用 ssh,插件经 opsAccess 解析档案,再经 ctx.shell 执行。档案的凭证通常来自其引用的 ssh-cred 条目(登记一次、多机共享)——合并在 resolve 时已完成,本工具永远只看到扁平字段。

  • 密钥登录(默认):BatchMode=yes 让任何需要交互的场景快速失败;StrictHostKeyChecking=accept-new 首次连接信任主机密钥、密钥变更则拒绝。
  • 密码登录(档案带 password):经 sshpass -f <密码文件> 执行,带 PreferredAuthentications=password、PubkeyAuthentication=no、NumberOfPasswordPrompts=1 — BatchMode 必须关闭,因为它会压制 sshpass 赖以应答的那个提示符。要求 dsh 宿主机上装有 sshpass。面向只提供密码登录的网络设备等场景。
  • 远程命令作为一个单引号参数整体传出 — 管道、重定向、&&、;、$() 全部在远程主机执行,本地 shell 绝不切分这行命令(2026-08-27 险情:一条未加引号的 && 链差一次认证失败就在本地删掉了控制面清单)。
  • 只有密钥/密码路径换成按次生成的凭据 token;user@host 和端口保持内联。展示命令(模型可见、入日志)只含 token — 真正执行的命令才带真实值。
  • 信号死亡(exitCode 为 null)归一化为 -1,原因写入 error 字段。可用 list_access 查看可选主机名。

设计

本包刻意保持单薄。所有共享机制 — 结果形状 { exitCode, stdout, stderr, command, error? }、输出 schema、render、按次解析的执行模板(默认 30s 超时)— 都在 @elinpf/dsh-ops-shell-tool。消费方工具只提供四个身份要素:工具名、凭据 kind、档案参数名、buildCommand。ops-access 缝隙每次调用经 ctx.get('opsAccess') 现取,绝不用静态 inject(preset 并发挂载同组插件,静态 inject 会让加载器死锁)。

  • src/index.ts — 插件本体(函数式插件:name/inject/Config/apply,无默认导出)。注册走 ctx.effect,fiber 销毁/HMR 时工具随之卸载。
  • src/types.ts — 纯类型(无任何运行时值)。
  • src/invariant.ts — invariant 伴随插件;无运行时 invariant(工具无状态,不拥有 session 事件),仅登记包的归属。

配置

- id: ops-tool-ssh
  name: '@elinpf/dsh-ops-tool-ssh'
  timeoutMs: 30000            # 单次调用的 shell 超时(毫秒)
  connectTimeoutSeconds: 10   # ssh -o ConnectTimeout(TCP 握手等待)

测试

npm run build
npx vitest run

测试用 mock 上下文(tests/harness.ts)挂载插件,捕获工具注册、shell resolve/run 调用和 effect disposer — 覆盖命令拼装、引号、凭据 token、错误兜底、render 纯函数性和 HMR 卸载。