npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

dsh-security-center

v1.1.9

Published

Security center for DeepSeek Harness: a read-only dashboard for the supply-chain and install-time security mechanisms the normal settings UI does not show (pnpm minimumReleaseAge cooldown/exemptions/strictness, trustPolicy, blockExoticSubdeps, trustLockfi

Readme

Security Center(安全中心)

把设置页里看不见的安全机制收拢到一处管理,并且只允许「交互式终端中的人工确认」修改。

它管理什么(这些机制原本没有任何 UI 入口)

| 机制 | 位置 | 削弱后的后果 | |---|---|---| | minimumReleaseAge | <profile>/pnpm-workspace.yaml | 关闭供应链冷却:刚发布(可能被投毒)的版本立即安装 | | minimumReleaseAgeStrict | 同上 | 范围内没有够老的版本时静默回退旧版本(「界面显示新版、实际装旧版」的成因) | | minimumReleaseAgeIgnoreMissingTime | 同上 | 不提供发布时间的注册表绕过冷却 | | minimumReleaseAgeExclude | 同上 | 列入的包/版本跳过冷却(版本过新时的官方解法) | | blockExoticSubdeps | 同上 | 间接依赖可从 git/tarball 直链拉取代码 | | trustLockfile | 同上 | 无条件信任 lockfile,被污染的 lockfile 直接进入 node_modules | | trustPolicy | 同上 | 发布信任等级降级的版本也能安装 | | allowBuilds | 同上 | 依赖在安装时执行任意代码(postinstall) |

说明:minimumReleaseAge 未显式配置时,pnpm 11 内置默认 1440 分钟(非严格)。

安全模型(本插件为什么这样做)

用户要求:拒绝所有非点击事件的操作;关闭安全机制/功能时警告后果、需确认才能改、取消即放弃。

实现方式(比点击更严格):

  1. 不注册任何 agent 工具、不注册任何命令 —— 模型没有任何句柄能碰到这些机制。
  2. 写入必须携带宿主服务的单次同意令牌:绑定「机制 + 值」、120 秒过期、用后作废。
  3. 令牌只能由 tools/security-center.mjs 在交互式终端(TTY)里取得:先打印后果说明,再要求人工输入 y。 AI 的 bash 调用不是 TTY → 直接以退出码 3 拒绝(已测试)。
  4. 所有应用动作进审计轨迹(securityCenter.audit())。

诚实边界:这套闸门关掉的是「模型/脚本/其他插件偷偷改安全设置」的路径;它不能防御已经能在你机器上以你身份执行任意交互式命令的攻击者——那种情况下什么都防不住。

用法

# 只读查看(任何环境都可以)
node <插件目录>/tools/security-center.mjs describe

# 修改(必须在你自己的交互终端里,会先警告再要求输入 y)
node <插件目录>/tools/security-center.mjs set minimumReleaseAge 1440
node <插件目录>/tools/security-center.mjs set minimumReleaseAge default   # 恢复内置默认(删键)
node <插件目录>/tools/security-center.mjs set minimumReleaseAgeExclude "[email protected],[email protected]"

默认 profile 为 desktop,可用 --profile <名称> 或 DSH_HOME 指定。

与「版本过新」的关系

pnpm 11 默认的 24 小时冷却会让刚发布的新版本装不上,并且因为默认非严格, 会静默回退到旧版本 —— 表现为「插件页显示新版本,装完却是旧版本」。三条出路:

  1. 安装时带精确版本(推荐):插件页输入 包名@x.y.z,管理器会把该版本写入冷却豁免;
  2. 用 set minimumReleaseAgeExclude 把该版本加入豁免(本插件,需人工确认);
  3. 等冷却窗口过去(默认 24 小时)后普通安装。

安全中心把这些机制看得见、可审计、且改不动于无形。

English

One page/CLI for the security mechanisms the settings UI never shows (pnpm minimumReleaseAge cooldown + strictness + exemptions, blockExoticSubdeps, trustLockfile, trustPolicy, allowBuilds). The plugin registers no agent tools and no commands; every write needs a single-use consent token that can only be minted from an interactive terminal after an explicit y confirmation, so an agent-driven shell (not a TTY) is refused outright. Read-only describe is safe anywhere.

License: MIT. Author: jd962.