npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

dsh-reach

v0.1.18

Published

Multi-channel decision & remote-control bridge for DeepSeek Harness: pushes any workspace's approval/question cards to IM channels (WeChat iLink first) and answers them from chat, with a session console, per-channel security, and an open push service.

Readme

dsh-reach

English | 简体中文 | Español | Português | हिन्दी

Multi-channel decision & remote-control bridge for DeepSeek Harness (DSH): pushes any workspace's approval/question cards to IM channels (WeChat iLink, Telegram, Feishu — plus QQ/DingTalk/WeCom v2 drop-in foundations) and answers them from chat, with a session console, per-channel security, and an open push service.

License OpenSSF Scorecard DSH plugin dsh-doctor DSH Market Gitee CI Version npm version npm downloads dshfind

Status: Phase 1–3 complete (WeChat + Telegram + Feishu channels, v0.1.18); v2 channel foundations (QQ/DingTalk/WeCom) on the open reachChannels registry. The design plan, competitor research, official contract verification, and phased roadmap live in docs/design/03-rebuild-direction-and-plan.md. Release (GitHub repo + npm publish) follows in a dedicated session.

📖 Ecosystem knowledge base — measured data, not marketing: plugin development guide · plugin-selection data · maintenance criteria.

⭐ 如果它帮到了你

这个插件是 DSH 插件家族的一员(40+ 个,全部 Apache-2.0)。如果你在用,给个 star —— 它不会解锁任何功能,但会让下一个人在搜索里更容易找到它。

English: part of a 40+ plugin family for DeepSeek Harness. If it is useful, a star helps the next person find it — nothing is gated behind it.

What is dsh-reach?

Full evidence, including the host-version compatibility matrix: dsh-plugin-supersession-review-20261005.md.

Terminal demo of dsh-reach: dsh-reach — install, then answer a decision card from chat

Animated terminal demo of dsh-reach

The same run, animated.

Maintenance status: 🧊 FROZEN

Frozen on 2026-10-05. No new features. This package still works, and it is not retired — but it no longer receives feature work. Only a genuine breakage will be fixed.

Maintainers treat this capability as one where better-adopted alternatives now exist, so effort has moved elsewhere. The comparison below was measured on 2026-10-05 and is recorded so nobody has to redo it.

| | package | weekly downloads | |---|---|---| | this package | dsh-reach | 600 | | better-adopted alternative | @xmanrui/dsh-im | 17,384 |

Why the alternative leads. @xmanrui/dsh-im provides ten channels — WeChat, Feishu, WeCom, DingTalk, QQ, Telegram, WhatsApp, Slack, Discord and Matrix.

Compatibility. declares no dsh peers, so the compatibility guard never blocks it.

What this package still does that the alternatives do not. this package's differentiator was that the same bridge carried approvals and questions back into chat; the rival is far broader in channel coverage

👉 For new work, prefer @xmanrui/dsh-im. Existing installs keep working unchanged; nothing is being removed.

Full evidence, including the host-version compatibility matrix: dsh-plugin-supersession-review-20261005.md.

Compatibility

| Surface | Status | |---|---| | Harness | DeepSeek Harness dsh-v0.2.1-alpha.1 (GitHub tag). Peer range >=0.1.2-rc.1 <0.2.0 \|\| >=0.1.5-alpha.1 <0.2.0 \|\| >=0.1.6-0 <0.2.0 \|\| >=0.1.7-0 <0.2.0; the dev/test pins deliberately stay on the published 0.1.7-rc.2 line, which is the face the typecheck:ci ruler measures (the plain typecheck ruler measures the checkout through tsconfig.json paths). Verified 2026-09-24 with the full gate chain; the bare-import + scratch-profile + keyless smoke run in the Compat workflow on every PR. | | Node | ^22.19.0 \|\| >=24.0.0 |

Features (Phase 1)

  • Cross-session decision push: approval/question cards from ANY workspace are mirrored to WeChat (iLink/ClawBot) with stable #token ids and P{n} numbering; reply 1/2, P1=1 P2=2, P1=Q1=2, or /rp /rq — answered through the native pending waterfall (first reply wins with the GUI).
  • Fail-closed security: first sender becomes the owner; empty allowlists deny everyone; unknown senders are audited and never answered.
  • Session console: /status /silent /notify /tasks /enter /history /stop /next /help plus native DSH command passthrough.
  • Proactive push: the reach_send tool with an outbound file fence; rate budget + FIFO re-queue; silent mode; background completion notices.
  • Settings tab: Settings → Plugins → IM Bridge (status, switches, re-scan/logout).
  • Open channel registry: third-party plugins register a channel via ctx.get('reachChannels').registerChannel({ id, adapter, priority, ownsChatId, startMonitor }); routing, outbound, and monitor lifecycle are all bridge-owned (QQ/DingTalk/WeCom ride this same path).

Install

dsh plugin --profile web add github:PerryLink/dsh-reach
# npm channel (published releases)
dsh plugin --profile web add dsh-reach

# git channel (latest main)
dsh plugin --profile web add github:PerryLink/dsh-reach

# alternates
npx @deepseek-ai/dsh plugin --profile web add dsh-reach
dsh1024 plugin --profile web add dsh-reach

Restart DSH after installation (bundle patches apply at startup).

Configuration

The profile row accepts these keys (Schemastery-validated; invalid values fail the load loudly):

| Key | Default | Description | |---|---|---| | crossSessionNotify | true | Push decision cards from ANY workspace/session (master switch) | | notifyTaskEvents | false | Background task finished/errored notifications | | cardTimeoutSec | 1800 | Decision-card soft timeout in seconds (0 = wait forever) | | approvalOnTimeout | delegate | Timed-out card policy: delegate (GUI chain) / reject / wait | | textChunkLimit | 4000 | Long reply chunk limit per message, in characters | | silent | false | Only final replies, no per-step streaming | | cwd | '' | Default working directory for new IM sessions ('' = host cwd) | | baseUrl / cdnBaseUrl / botType | iLink defaults | WeChat gateway, media CDN, bot type | | allowFrom | [] | Sender allowlist (empty = fail-closed; first sender = owner) | | queueMode | queue | Busy delivery: queue or steer | | maxQueue / sendBudget / windowSec | 50 / 10 / 60 | Queue cap, per-window send budget, window seconds | | denyUnauthorized | false | Silently ignore (true) or notice (false) unknown senders | | authCode | '' | Shared secret the IM side must present before a message is accepted | | digestSec | 300 | Digest window in seconds (0 disables the digest) | | pushToken | '' | Token for the open push service (reach_send HTTP surface) | | telegramToken | '' | Telegram bot token for the Telegram channel |

Development

pnpm install
pnpm run typecheck && pnpm run typecheck:ci && pnpm test
pnpm run build && pnpm run verify:self-contained && pnpm run verify:artifacts
pnpm run check:readmes && pnpm pack

Install from the DSH Desktop Market

All PerryLink plugins are browsable in the built-in DSH Desktop Market: Market → Sources → add source → paste https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json → select it. Installation still goes through the Market's npm-identity verification and your confirmation.

Interoperability with other DSH plugins

Verified against DSH 0.2.0-rc.2 (the runtime this README ships for) and the high-star plugin set surveyed on 2026-10-05.

This plugin does not interfere with other plugins, including the widely installed high-star ones:

  • No tool-name collision. Every tool is namespaced; no bare name owned by a shipped tool or another plugin is registered.
  • No service-key collision. It provides reach, reachChannels, reachPush; those keys are not a built-in seam and are not provided by any surveyed high-star plugin.
  • No slot collision. It registers no client slot key, so it cannot contend for a shadows-shipped-ui seat.
  • No HTTP route collision. It registers no webServer prefix.
  • No patch-layer collision. The bundle patch only inserts its own row; it never overrides a built-in row's config.
  • No global mutation. It does not patch prototypes, rewrite process.env, or replace the global fetch dispatcher.

Shared event listeners are non-interfering by construction. It observes the ordering-sensitive events approval/request, user-questions/request with ctx.on() — Cordis's broadcast registration, where every listener runs and none can starve another. Every listener here delegates through next(), so the chain is never short-circuited, and a mutation is applied to the value next() produced rather than returned in its place:

Static evidence: dsh-plugin-doctor K10–K13 report pass for every check on this repository.

PerryLink DSH Plugin Family

This project is one of the 33 actively maintained DeepSeek Harness plugins from PerryLink — the roster is 42, of which 6 are frozen and 3 retired; every one keeps its row below, with the reason in the Status column. If this one helps you, the others likely will too:

| Plugin | One-liner | Status | |---|---|---| | dsh-auto-review | Second-model auto-review on the approval chain, fail-closed by default | | | dsh-autotier | Automatic strong/cheap model-tier routing with deterministic risk guards and a /tier command | | | dsh-background-agents | Durable background child agents with a Web UI sidebar, messaging and interrupt | 🚫 RETIRED — see the note above | | dsh-budget | Cost governance for DeepSeek Harness: budgets, carbon, and latency in one panel. | 🧊 FROZEN — see the repo README | | dsh-catalog | DSH Desktop Market standard catalog source for the PerryLink family | | | dsh-cert-mcp | Read-only MCP server exposing the certification registry: grades, snapshots and five-dimension evidence | | | dsh-checkpoint-rewind | Claude Code /rewind-equivalent: snapshots, session forks, one-shot restore | | | dsh-claude-move | Migrate Claude Code sessions, memory, skills and CLAUDE.md into DSH | 🧊 FROZEN — see the repo README | | dsh-click | Cross-platform native desktop control for DeepSeek Harness — Windows first. | | | dsh-composer-history | Terminal-style input history for the web composer: arrows, Ctrl+R search | | | dsh-data-quality | Dataset quality checks and citation cross-checks (the optional numeric bridge consumed here) | | | dsh-defend | Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness. | 🧊 FROZEN — see the repo README | | dsh-doublecheck | Engineering-discipline guard: requirements grill, test gates, adversary review | | | dsh-draw | Unified static-image generation routing for DeepSeek Harness. | 🧊 FROZEN — see the repo README | | dsh-fast | Read-only performance diagnostics for DeepSeek Harness. | | | dsh-fund-research | Deterministic research reports for Chinese public mutual funds | | | dsh-github | GitHub PR/issues integration for DSH, every write gated by approval | | | dsh-industry-research | Industry research orchestration that seals its deliverables through this plugin's ctx.researchReport.assemble | | | dsh-laya | Laya typed decisions (noul/choice/score) as a first-class Cordis service and model-visible tools | | | dsh-library | Local document knowledge base for DeepSeek Harness. | | | dsh-local-ai | Local-model (Ollama) integration for DeepSeek Harness. | | | dsh-lsp-actions | LSP diagnostics, formatting, completion, code actions and rename over language servers | | | dsh-mask | PII masking middleware: anonymize at the model boundary, restore at the display layer | | | dsh-mcp-panel | Read-only MCP runtime panel: /mcp command + Settings tab with status, tools and errors | | | dsh-memento | Approval-gated cross-session memory: ctx.memory seam + SQLite + memory tool | 🧊 FROZEN — see the repo README | | dsh-observe | OpenTelemetry and Langfuse observability exporter for DeepSeek Harness. | | | dsh-output-styles | Claude Code outputStyles-equivalent runtime style switching | | | dsh-permission-rules | Claude Code-style declarative allow/deny/ask permission rules with audit | | | dsh-plugin-certification | Community certification registry with repro-checkable grades and badges | | | dsh-plugin-doctor | Zero-dependency static + sandbox smoke detector for DSH plugins | | | dsh-plugin-guide | Plugin-development knowledge base as an on-demand agent skill | | | dsh-plugin-kit | Shared zero-runtime-dependency toolkit for the PerryLink DSH plugins | | | dsh-plugin-upgrade | One-package, one-corridor-index plugin upgrade skill: routes a repository to the matching closed corridor card | | | dsh-plugin-upgrade-015 | Merged 0.1.3-alpha.1 → 0.1.5-rc.1 upgrade corridor card plus a zero-dependency seam scanner | 🚫 RETIRED — corridors carried by dsh-plugin-upgrade | | dsh-reach | Multi-channel approval/question bridge: WeChat/Telegram/Feishu, session console | 🧊 FROZEN — see the repo README | | dsh-research-report | Verifiable research-report engine: content-addressed evidence ledger and sealed versions | | | dsh-score | Multi-dimensional quality scoring for DeepSeek Harness plugins. | | | dsh-session-pin | Pin sessions in the Web sidebar with durable ordering | 🚫 RETIRED — see the note above | | dsh-session-sync | Cross-device session sync for DeepSeek Harness — a dedicated git mirror of your session store. | | | dsh-skill-pack-security | Security-audit skill pack: secret scan, dependency and supply-chain review | | | dsh-talk | Voice-first session loop for DeepSeek Harness: talk to it, hear it answer. | | | dsh-team-rooms | Cross-session team rooms: shared message bus, task board and timeline | 🚫 RETIRED — see the note above | | dsh-test-drive | Isolated install-and-smoke test drives for DeepSeek Harness plugins. | | | dsh-ticktick | TickTick/Dida365 task bridge: session-header panel + 11 tools | | | dsh-translate | Vendor parameter translation and deterministic JSON repair for DeepSeek Harness. | |

Install from the DSH Desktop Market

All PerryLink plugins are browsable in the built-in DSH Desktop Market: Market → Sources → add source → paste https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json → select it. Installation still goes through the Market's npm-identity verification and your confirmation.

License

Apache-2.0. Third-party notices in THIRD_PARTY_NOTICES.md.