npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

create-deepseek-harness-action

v0.5.0

Published

Create safe DeepSeek Harness GitHub workflows

Downloads

1,293

Readme

create-deepseek-harness-action

Create safe starter workflows for DeepSeek Harness Action.

npm create deepseek-harness-action@latest

The interactive installer offers PR Review, @dsh Coding Commands, or Both, or Automatic Session, then lets you keep the compatible controlled DSH composition or explicitly select native. For non-interactive use, select the workflow mode explicitly; omitting --dsh-mode keeps controlled:

npm create deepseek-harness-action@latest -- --mode both

To generate native-mode workflows explicitly:

npm create deepseek-harness-action@latest -- --mode both --dsh-mode native

Valid workflow modes are review, commands, both, and session; valid DSH modes are controlled and native. The installer creates only workflow files. It does not add secrets, commit, push, or open a pull request. Existing workflow files are never overwritten.

Automatic Session creates .github/workflows/dsh-session.yml with matching run-name, concurrency and key bindings. Commit it to the default branch, dispatch there with a lowercase key and a new prompt, then reuse the key for follow-ups:

npm create deepseek-harness-action@latest -- --mode session

This starter uses read-only authority and needs contents: read and actions: read. It requires no source run ID. A previous failed or unknown run, or a missing, expired, corrupt or incompatible checkpoint must be reconciled before continuing. See the Session contract for boundaries and explicit usage.

Installer 0.5.0 accepts explicit maintainer-selected write validation:

npm create deepseek-harness-action@latest -- --mode commands \
  --test-commands '[["node","trusted-tests.mjs"]]' \
  --container-image 'your-reviewed-image@sha256:<64 lowercase hex>'

Choose commands and their trusted sources yourself. No repository scripts are discovered, executed or automatically trusted; no language or package manager is assumed. Missing options keep the fail-closed placeholder. Malformed/empty argv, workflow expressions, placeholders and mutable image references are rejected. Installing these values still requires successful Controller validation and fresh actor/repository/SHA authorization at runtime. The installer reports credentials/scopes/quota, Docker/image availability and repository validation as unchecked.

For an offline static check from a reviewed Action source checkout, use npm run check:config -- --config examples/config-check.json as described in Setup.

Version 0.5.0 is prepared for the formal v0.10.0 Action release at immutable commit 9c52f682bbeed1b7752a9e21273e6c13b01e79b1. Its formal controlled/native release canary passed. Installer source review, exact-source CI/tag, qualified tarball, npm publication and fresh public consumers remain distinct gates. The Action identity alone does not establish installer publication or consumer qualification.

The verified Action commit is supplied through DSH_ACTION_RELEASE_SHA at pack time. Source templates retain a controlled build token; generated workflows never use a candidate SHA, floating tag, or branch. Their audited exact DSH pin is 0.2.0-rc.2, with controlled as the default and native selected explicitly.