Nx Run Tasks
nomcopter/react-mosaic
Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.
Execute an explicitly authorized dsh-web release, or consult release-specific compatibility gates and recovery guidance without publishing.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add zhu1090093659/dsh-web --skill dsh-web-release -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install zhu1090093659/dsh-web dsh-web-release --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/zhu1090093659/dsh-web.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dsh-web-release .claude/skills/dsh-web-release && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dsh-web-release" agent skill from https://github.com/zhu1090093659/dsh-web/tree/dev/.agents/skills/dsh-web-release into .claude/skills/dsh-web-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-web-release", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/zhu1090093659/dsh-web/tree/dev/.agents/skills/dsh-web-releaseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add zhu1090093659/dsh-web --skill dsh-web-release -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install zhu1090093659/dsh-web dsh-web-release --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhu1090093659/dsh-web.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/dsh-web-release .agents/skills/dsh-web-release && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dsh-web-release" agent skill from https://github.com/zhu1090093659/dsh-web/tree/dev/.agents/skills/dsh-web-release into .agents/skills/dsh-web-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-web-release", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zhu1090093659/dsh-web --skill dsh-web-release -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install zhu1090093659/dsh-web dsh-web-release --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhu1090093659/dsh-web.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/dsh-web-release .cursor/skills/dsh-web-release && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dsh-web-release" agent skill from https://github.com/zhu1090093659/dsh-web/tree/dev/.agents/skills/dsh-web-release into .cursor/skills/dsh-web-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-web-release", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/zhu1090093659/dsh-web.git --path .agents/skills/dsh-web-release--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add zhu1090093659/dsh-web --skill dsh-web-release -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install zhu1090093659/dsh-web dsh-web-release --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhu1090093659/dsh-web.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/dsh-web-release .gemini/skills/dsh-web-release && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dsh-web-release" agent skill from https://github.com/zhu1090093659/dsh-web/tree/dev/.agents/skills/dsh-web-release into .gemini/skills/dsh-web-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-web-release", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install zhu1090093659/dsh-web dsh-web-releaseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add zhu1090093659/dsh-web --skill dsh-web-release -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/zhu1090093659/dsh-web.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/dsh-web-release .github/skills/dsh-web-release && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dsh-web-release" agent skill from https://github.com/zhu1090093659/dsh-web/tree/dev/.agents/skills/dsh-web-release into .github/skills/dsh-web-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-web-release", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zhu1090093659/dsh-web --skill dsh-web-release -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install zhu1090093659/dsh-web dsh-web-release --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhu1090093659/dsh-web.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/dsh-web-release .opencode/skills/dsh-web-release && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dsh-web-release" agent skill from https://github.com/zhu1090093659/dsh-web/tree/dev/.agents/skills/dsh-web-release into .opencode/skills/dsh-web-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-web-release", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dsh-web-releaseExecute an explicitly authorized dsh-web release, or consult release-specific compatibility gates and recovery guidance without publishing.
Dsh Web Release is an agent skill from zhu1090093659/dsh-web. Execute an explicitly authorized dsh-web release, or consult release-specific compatibility gates and recovery guidance without publishing. Loading this skill, CI repairs, and version audits do not authorize a release.
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. It works with npm. The repository describes itself as: DeepSeek Harness (DSH) Web 插件聚合生态 · 万物皆插件,通过创意工坊分发||DeepSeek Harness (DSH) Web Plugin Aggregation Ecosystem · Everything is a plugin, distributed via the Creative Workshop. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8661221. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitpnpmnpmnodeghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, pnpm, npm and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
NPM_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dsh Web Release loads about 4.1k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 854 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
-checks --access public`(NPM_TOKEN 写入 ~/.npmrc,拓扑序发布,workspace:* 自动转真实版本;private 包由 pnpm 自动跳过——若某 private 包被聚合依赖引用,先解除引用Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from zhu1090093659/dsh-web at commit 8661221, republished under its Apache-2.0 licence (© zhu1090093659). 854 words, ~4,111 tokens.
.claude/skills/dsh-web-release/SKILL.md (or your agent's skills folder).本技能固化 dsh-web 全家桶的完整发版流程:全仓统一版本(四个卫星仓先发同版本)→ 提交 → 打 tag → 推送触发 GitHub Actions 发布管线(构建/测试/npm 发布/GitHub Release)→ 发布后验证。
main、创建/推送 tag、npm publish、创建/修改 GitHub Release 或触发发布 dispatch。NPM_PUBLISH_ENABLED、已有 tag、历史发布许可和 CI 全绿均不是当前发布授权。scripts/lib/family-packages.mjs 得到,版本与包数量以 node scripts/verify-version.mjs X.Y.Z 的输出为准,不在技能中手抄固定数量;全部发布到 npm scope @linxin666,registry 固定 registry.npmjs.org。X.Y.Z,且卫星先发、本仓后发。已有版本不追溯,对齐只从下一个版本开始。vX.Y.Z tag 为上一版本,
默认目标为下一个补丁版本 X.Y.(Z+1)。用户明确给出版本号,或明确要求 major/minor/prerelease
变更时,按该要求执行;远端 tag 与 npm 已发布版本不一致时,按下方失败恢复规则处理,不自行猜测。NPM_TOKEN
(npm automation token,@linxin666 scope);本机 npm 登录态不固定(无登录态时
npm whoami 401 属正常;本机当前以 linxin666 登录),发版不依赖本机登录态。NPM_PUBLISH_ENABLED: 'true';发布管线执行完整门禁、版本校验后运行
pnpm -r publish --tag latest 与 legacy 双发(均以该开关门控),发布后立即用
scripts/verify-registry.mjs 断言每个家族包的 tag 版本都能从 registry 解析
(带重试预算,覆盖 npm 传播延迟)。开关曾因家族跟踪未上 npm 的
@deepseek-ai/* alpha cohort 而被暂停(决策记录
.agents/notes/archived/process/2026-08-28-pause-release-npm-publish-unstable-dsh-alpha.md,
恢复记录
.agents/notes/archived/process/2026-08-30-restore-npm-publish-alpha.2.md)。
若将来 cohort 再次无法从 registry 解析,把开关改回 'false',tag 推送即退回
GitHub-Release-only(此时 mount smoke 的 auto 模式以 workspace 打包的 file:
tarball 验证本 tag 构建)。pnpm -r publish 自动跳过。它的 version 与家族包同步 bump:git / link 安装仓库根别名 bundle 时,插件管理器显示的就是它。dev 是开发分支(集成分支),本地开发与远程 PR 统一以
dev 为目标(远端默认分支);main 是稳定分支(发布分支),只接收
dev 上测试通过后合入的代码,发版 tag 一律从 main 打。dev /
main 均已启用分支保护(要求 PR + CI 全绿;管理员可绕过,维护者直推
仍可用,功能改动仍须先经 dev)。在修改版本号、合并到 main、创建或推送 tag 之前,先按第 1 节确定 PREVIOUS_VERSION 与 TARGET_VERSION,再完成本审计;全新安装成功不能替代存量用户自动升级成功。
自动升级至少要覆盖两条真实路径:plugin-manager 的 check-updates → update 路径,以及 Doctor 启动 DSH 前的自动迁移路径;如果某种启动方式绕过迁移器,必须明确标为不支持,并在 release notes 写出恢复方式,不能默认为兼容。
以 PREVIOUS_TAG..HEAD 的实际 diff、目标 npm tarball 和当前 profile 格式为依据,逐项检查以下兼容面:
name、exports、dsh.bundle / cordis.patch.yml、dsh.client、浏览器 loader id、聚合包 self row、旧包别名和迁移元数据。$DSH_HOME/profiles/*/package.json、pnpm-lock.yaml、dsh.profile.bundles、cordis.patch.yml、disabled 覆盖行、bundle 顺序和官方 CLI 写入行为。@deepseek-ai/* 公共 API、服务注入、模块表、DSH 最低版本、Node 版本、CLI 参数、进程启动和退出语义。包声明的 dsh.engines.dsh 下限必须不高于发布验证所使用的 DSH 版本;CI 固定版本低于声明下限时阻断发布。plugin-manager 与 Doctor 的 DSH 兼容判定必须一致,或在支持矩阵中明确差异与限制。dsh web;直接入口若绕过 Doctor 迁移,必须补齐迁移或在 release notes 给出明确的不支持声明和人工恢复步骤。两条自动迁移路径的安装顺序、目标版本、回滚结果必须一致,不能只在一条路径修复。lib/、aggregate manifest、market / skin 产物、npm 包内文件白名单;不能只检查源码而漏掉实际 tarball。对每个变化记录 旧标识 → 新标识、唯一迁移 owner、读取旧值和写入新值的顺序、备份位置、回滚动作、幂等条件和验证断言;没有变化的持久化标识符也要明确写为 frozen,不要凭猜测重命名。
将每个变更归类为:无需迁移的向后兼容、带确定性迁移的兼容变更、或必须阻断自动升级的不兼容变更。带迁移的变更必须满足:目标资源先可用、只有官方写入器修改 profile、旧数据在目标安装并通过启动 / dump-config 预检前不删除、迁移可重复执行、失败能恢复备份、失败后不会留下双挂载 / 重复 row / 半写配置。
当前 @linxin666/dsh-web-ui-all → @linxin666/dsh-web-all 过渡以 packages/dsh-plugin-manager/src/host/legacy-migration.ts 和对应 Agent Note 为迁移映射的事实源;只有在过渡窗口仍有效且目标包已从 registry 验证可读时才双发布旧名,窗口结束后停止旧包发布并执行 deprecate,不要无条件重复发布已占用版本,也不要手工改写当前包替代迁移测试。
使用隔离的临时 DSH_HOME 和官方 CLI,禁止把当前用户 profile 或运行中的 DSH 服务当作测试夹具。至少验证:
--dump-config 后确认数据和功能仍在。发布前至少执行以下门禁,并把针对本次迁移的测试文件和证据一并纳入提交:
pnpm sync-shared:check
pnpm typecheck
pnpm test
pnpm test:scripts
pnpm aggregate:check
pnpm runtime-deps:check如果缺少旧 profile fixture、失败注入或跨平台验证,不能用“测试暂缺”放行 tag;先补测试 / 修复迁移,或把该版本明确降级为不支持自动升级并提供可执行的人工恢复步骤。
出现以下任一情况,立即停止版本 bump、tag 和 npm publish:持久化或线协议标识符发生变化但没有映射;迁移不是幂等事务或没有备份 / 回滚;目标包尚未验证可用就删除旧包;更新路径与启动路径的迁移语义不一致;升级后出现双挂载、重复 row、配置丢失或锁文件半写;只验证了 fresh install;或失败后只能依赖手工编辑 profile 才能恢复。
兼容性修复完成后必须同步更新行为测试、对应 Agent Note 和双语 release notes;不要通过改成 major 版本、跳过自动升级检查或先发布后观察来绕过阻断条件。
cd /Users/zcl/code/dsh-web
git checkout dev # 本地工作分支以 dev 为基线(远端默认分支)
git fetch origin && git rebase origin/dev # 先同步上游最新 dev
git status --short # 明确本次要提交的内容,无意外文件
pnpm test # 全仓测试
pnpm test:scripts # 脚本测试(link-profile 等)
pnpm runtime-deps:check # 发布包运行时依赖安全门禁
node scripts/aggregate.mjs --check # 聚合清单与磁盘一致(改过 aggregate.yml 时必须先重跑生成)
pnpm market:check # market/dist 与已提交产物一致
git log --oneline -5 # 确认包含本次全部改动、无未推送提交发版前提:待发布的全部改动先合入 dev 并在 dev 上全绿;发版时把
dev 合入 main(见第 3 节),tag 从 main 打。
卫星仓(dsh-skins / dsh-pet / dsh-community-plugins / dsh-presets)的改动不经过本仓发布:它们在各自仓库评审、提交并打 tag,发布时与本仓同版本(见第 2 节),市场内容按 submodule gitlink 固定的提交拉取(见 docs/publish-prep.md)。
版本 bump 后必须重建产物并同步市场资产(版本信息影响 bundle 内容):
pnpm build # 全仓重建 lib 产物(含新版本号)
pnpm market:build # 重新生成 market/dist(manifest.js/styles.js 内嵌产物内容)
pnpm market:check # 必须通过;产物与市场资产要同一次构建一起提交X.Y.Z,或明确要求 major/minor/prerelease 变更时,以该要求为准,并确认目标版本未在 npm 发布过。PREVIOUS_TAG="$(
git ls-remote --tags --refs --sort=-version:refname origin 'v*' \
| awk '$2 ~ /^refs\/tags\/v[0-9]+\.[0-9]+\.[0-9]+$/ { sub("refs/tags/", "", $2); print $2; exit }'
)"
test -n "$PREVIOUS_TAG" || { echo "No previous release tag"; exit 1; }
PREVIOUS_VERSION="${PREVIOUS_TAG#v}"
test "$(npm view "@linxin666/dsh-web-all@$PREVIOUS_VERSION" version)" = "$PREVIOUS_VERSION" \
|| { echo "Remote tag and npm publication disagree"; exit 1; }
IFS=. read -r MAJOR MINOR PATCH <<EOF
$PREVIOUS_VERSION
EOF
TARGET_VERSION="$MAJOR.$MINOR.$((PATCH + 1))"
printf 'Previous release: %s; default target: %s\n' "$PREVIOUS_VERSION" "$TARGET_VERSION"TARGET_VERSION 即后续命令中的 X.Y.Z。如果没有可确认的上一正式发布,或远端 tag 和 npm
记录不一致,不编造版本号;先按下方失败恢复规则处理。
find packages -name package.json -not -path '*/node_modules/*' \
-exec sed -i '' 's/"version": "[0-9][^"]*"/"version": "X.Y.Z"/' {} +
sed -i '' 's/"version": "[0-9][^"]*"/"version": "X.Y.Z"/' package.json
sed -i '' 's|"@linxin666/dsh-web-all": ".*"|"@linxin666/dsh-web-all": "^X.Y.Z"|' package.json
find packages package.json -name package.json -not -path '*/node_modules/*' \
-exec grep -H '"version"' {} \; | grep -v '"version": "X.Y.Z"' # 必须无输出
grep -H '"@linxin666/dsh-web-all"' package.json # 必须是 "^X.Y.Z"(根依赖基线随 tag 走)
pnpm install --lockfile-only --ignore-scripts # 刷新锁文件里该依赖的 specifierpnpm-lock.yaml 不记录家族包的 version,无需为它们改动;家族包依赖用 workspace:*,发布时由 pnpm
自动替换为实际版本,无需手工改依赖链。根别名是例外:它的聚合包依赖是基线随 tag 走的 caret 范围
(^X.Y.Z,见 root alias caret Note),
基线搬动后锁文件的 specifier 要一起刷新。卫星包不是 workspace 包,它们的依赖范围与锁文件条目在第 2 节随对齐一起更新。
从下一版本起,四个卫星仓与本仓发布同一个 X.Y.Z,且卫星先发、本仓后发:聚合包把卫星作为 npm 外部行依赖(范围手写在 packages/dsh-web-all/package.json),本仓 CI 的 pnpm install --frozen-lockfile 只能解析 registry 上已存在的版本。卫星此前的 0.3.25 版本线不追溯,对齐从 TARGET_VERSION 一次性完成。
| 卫星仓 | npm 包 | 本仓检出 |
|---|---|---|
| dsh-skins | @linxin666/dsh-client-ui-skin-center | satellites/dsh-skins |
| dsh-pet | @linxin666/dsh-pet | satellites/dsh-pet |
| dsh-community-plugins | @linxin666/dsh-client-ui-community-plugins | satellites/dsh-community-plugins |
| dsh-presets | @linxin666/dsh-client-ui-preset-center | satellites/dsh-presets |
每个卫星仓按自己的分支模型与门禁重复同一套步骤(其 release.yml 会拒绝 package.json 与 tag 不一致的发布):
cd <卫星仓检出>
git checkout main && git pull origin main
# 1. 该仓 package.json 的 version 改成同一个 X.Y.Z,并重建该仓自己的产物
# 2. 双语 release notes 写入该仓 docs/release-notes/vX.Y.Z.md
# 3. 提交、推 main、打 tag 并推送,触发该仓 release.yml
git tag "vX.Y.Z" && git push origin main && git push origin "vX.Y.Z"
# 4. 断言 registry 已解析(各仓管线自带重试,这里只做最终复核)
npm view <该仓包名>@X.Y.Z version四个卫星版本都能从 registry 解析之后,才回到本仓完成对齐,再进入第 3 节:
# packages/dsh-web-all/package.json:卫星依赖范围改成 ^X.Y.Z(外部行版本手写并随生成器保留)
# pnpm-workspace.yaml 的 minimumReleaseAgeExclude:卫星条目改成 @X.Y.Z
pnpm install # 刷新 pnpm-lock.yaml,锁文件解析已发布的卫星版本
node scripts/aggregate.mjs --check # 外部行依赖范围与清单一致
for d in satellites/dsh-skins satellites/dsh-pet satellites/dsh-community-plugins satellites/dsh-presets; do
git -C "$d" fetch origin main
git add "$d" # gitlink 移到该仓本次发布提交,市场内容与发行版本一致
done失败处理:
发版提交与 tag 在 main 上执行(tag 从 main 打);打 tag 前先确保
main 已包含全部待发布内容(= dev,含版本 bump 前的一切功能改动):
git checkout main && git pull origin main
git merge --ff-only dev # dev 已全绿,main 应能快进(非快进说明 main 有独有提交,先核对再合)
git push origin main # 分支保护允许管理员直推;非管理员走 PR:dev -> main提交按两类拆分(保持历史可读):
# 修复/功能改动(含构建产物 lib/*.js 与聚合重生成的 cordis.patch.yml)
git add <修复文件...>
git commit -m "fix(...): <改动摘要>"
# 双语 notes(v0.2.6 起强制,中文默认 + English 折叠):先跑脚本出草稿(两视图条目相同,
# 均为原始提交主题),再由维护者(AI)逐条翻译——默认视图译成中文、English 折叠视图
# 译成英文,存 docs/release-notes/vX.Y.Z.md(管线优先用该文件)
node scripts/release-notes.mjs "vX.Y.Z" > /tmp/notes-draft.md
# 维护者翻译后写入 docs/release-notes/vX.Y.Z.md;对已发布版本用
# gh release edit "vX.Y.Z" --notes-file docs/release-notes/vX.Y.Z.md 校正
# 发版提交:全部家族 package.json 版本 bump + 发布相关变更(管线、skill、AGENTS.md、.agents/notes/)
# + docs/release-notes/vX.Y.Z.md
git add packages/**/package.json .github/workflows/release.yml .agents/skills/ AGENTS.md .agents/notes/ docs/release-notes/
git commit -m "chore(release): bump to X.Y.Z"
git tag "vX.Y.Z" # tag 命名固定 v 前缀;tag 即版本事实源
git push origin main
git push origin "vX.Y.Z" # 推送 tag 即触发发布管线(唯一发布开关)
# 发布后把 main 合回 dev(版本 bump 与 notes 提交也进入 dev),保持双分支一致
git checkout dev && git merge main && git push origin dev推送 v* tag 后 GitHub Actions 自动执行,顺序:
market:check;runtime-deps:check 是发布前的运行时依赖安全门禁;node scripts/verify-version.mjs X.Y.Z,由 scripts/lib/family-packages.mjs 遍历 packages/ 的全部家族包并逐一比对 tag 版本;数量以脚本输出为准,不手抄固定数字。该校验只看本仓 packages/,卫星仓的同版本由第 2 节各仓自己的 tag 校验与第 5 节复核覆盖;docs/release-notes/$TAG.md(v0.2.6 起维护者在发版提交中附带中文默认 + English 折叠的双语版,管线直接采用);文件缺失时兜底跑 node scripts/release-notes.mjs $TAG 生成双视图草稿(把上一 tag 以来的全部常规提交——含合并进来的分支提交,不能只走 --first-parent,v0.1.15 曾因此漏掉整条 perf/refactor 分支——分组为新功能 / 修复 / 其他改动并链接 issue,中文默认视图与 English 折叠视图条目相同、均为原始提交主题)。发布前执行,失败即中止,不触碰 npm;pnpm -r publish --no-git-checks --access public(NPM_TOKEN 写入 ~/.npmrc,拓扑序发布,workspace:* 自动转真实版本;private 包由 pnpm 自动跳过——若某 private 包被聚合依赖引用,先解除引用或改为公开,否则全家桶安装 404),随后 node scripts/verify-registry.mjs <tag版本> 断言每个家族包的该版本都能从 registry 解析:pnpm 的逐包成功行不是信任边界,registry 传播会滞后数分钟(v0.3.18 实测约 10 分钟)甚至静默丢版本,而挂载冒烟的 auto 改写会用 workspace tarball 掩盖缺失的家族依赖;断言失败即中止,不进入 legacy 双发与 GitHub Release;node scripts/publish-legacy-aggregate.mjs <tag版本> 发布旧聚合包 @linxin666/dsh-web-ui-all;脚本必须有窗口计数 / 跳过已发布版本的保护。窗口结束后不得继续发布旧包,改为执行一次 npm deprecate @linxin666/dsh-web-ui-all "迁移到 @linxin666/dsh-web-all;详见该版本 Release notes" 并核对 deprecation 元数据;gh release create --notes-file 创建 GitHub Release(notes 即第 4 步生成的内容);Release 只保留 GitHub 自动源码归档,不附 npm tarball(与官方 DSH 一致,v0.2.4 起约定)。关注与排障:
gh run watch # 跟踪最新 run
gh run list --workflow=release.yml # 查历史NPM_TOKEN secret 缺失/过期 → 到仓库 Settings → Secrets and variables → Actions 更新后再重跑。npm deprecate 标记弃用并立即发下一个补丁版本,不尝试覆盖。# NPM_PUBLISH_ENABLED='true':期望 = X.Y.Z
npm view @linxin666/dsh-web-all version
# 卫星仓同版本(第 2 节已断言一次,这里是发布后复核):四个都必须等于 X.Y.Z
for p in @linxin666/dsh-client-ui-skin-center @linxin666/dsh-pet \
@linxin666/dsh-client-ui-community-plugins @linxin666/dsh-client-ui-preset-center; do
printf '%s -> %s\n' "$p" "$(npm view "$p@X.Y.Z" version)"
done
# 仅在双发窗口内执行:
npm view @linxin666/dsh-web-ui-all version # 期望 = X.Y.Z
# 窗口结束后:旧包版本应保持窗口末版本,且 deprecated 字段必须非空
npm view @linxin666/dsh-web-ui-all deprecated
gh release view "vX.Y.Z" --json body --jq .body # Release 已创建;v0.2.6 起默认视图为中文、English 折叠视图为英文(逐条抽查)
gh run list --workflow=release.yml # 全部成功
git ls-remote --tags origin | grep "vX.Y.Z" # tag 已在远端dev(本地开发与远程 PR 的目标分支),
dev 全绿后才合入 main;发版 tag 只从 main 打,发布后把 main
合回 dev。分支保护下非管理员无法直推 main / dev,维护者直推
仍可用(管理员绕过),但功能改动仍须先经 dev。EN / 中文 混排。双语 notes 作为
docs/release-notes/vX.Y.Z.md 随发版提交入库,管线优先使用;漏提交时脚本草稿兜底
(两视图均为原始提交主题),但发布后必须立即用 gh release edit 校正为
「中文默认 + English 折叠」双语,不得保留未翻译条目。notes 正文不得出现裸的
@org token(如 @deepseek-ai):GitHub 会渲染成 mention 并把该账号列进
release 页的 Contributors 框(v0.3.14 事故);脚本渲染路径已自动加反引号转义,
维护者手写条目也必须用反引号包裹(release 页面同理,发布后抽查
user-mention 是否为 0)。桌面安装包由 desktop-release.yml 在 tag 推送后
自动构建并上传到 Release(dispatch 可为存量 tag 补发,ref 输入可指定
构建分支)。© zhu1090093659, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/dsh-web-release of zhu1090093659/dsh-web.
Open the folder on GitHubat commit 8661221
Dsh Web Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dsh Web Release this skillzhu1090093659/dsh-web | 8.6k | — | ~4.1k | Automated safety check: Warn | Apache-2.0 | |
| Nx Run Tasksnomcopter/react-mosaic | 4.8k | 8 repos | ~613 | Automated safety check: Pass | Custom licence | |
| Migrate Internal Package into GhostTryGhost/Ghost | 56k | — | ~3.8k | Automated safety check: Pass | MIT | |
| Open Code Review CLIalibaba/open-code-review | 46k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Cutting A ReleaseTriliumNext/Trilium | 38k | — | ~3.2k | Automated safety check: Pass | AGPL-3.0 | |
| Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop | 5.4k | — | ~2.2k | Automated safety check: Pass | MIT |
nomcopter/react-mosaic
Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.
TryGhost/Ghost
Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.
alibaba/open-code-review
Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.
TriliumNext/Trilium
A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.
dmmulroy/anti-slop
Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.
alibaba/open-code-review
Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.
zhu1090093659/dsh-web
Develop a DSH community plugin in the contributor's own repository, and register it in the community plugin index owned by the dsh-community-plugins repository — the index is community.json at that…
zhu1090093659/dsh-web
A skill your agent uses when adding or editing dsh-web README files, docs, AGENTS.md instructions, user-facing configuration text, or bilingual documentation pairs.
zhu1090093659/dsh-web
A skill your agent uses for implementation, maintenance, or configuration in dsh-web; scope the change and load only its relevant workflow.
zhu1090093659/dsh-web
A skill your agent uses when reviewing uncommitted changes, a branch, or a pull request for dsh-web.
zhu1090093659/dsh-web
Use before pushing, opening or updating a pull request, or claiming dsh-web checks pass.
zhu1090093659/dsh-web
A skill your agent uses to validate a dsh-web client or skin change in the real DeepSeek Harness Web GUI, including build readiness, responsive rendering, interaction checks, and evidence capture.
Works with
Categories
Execute an explicitly authorized dsh-web release, or consult release-specific compatibility gates and recovery guidance without publishing. Dsh Web Release is an agent skill from zhu1090093659/dsh-web. Execute an explicitly authorized dsh-web release, or consult release-specific compatibility gates and recovery guidance without publishing.
Dsh Web Release fits situations like: development work in your project.
Run `npx skills add zhu1090093659/dsh-web --skill dsh-web-release -a claude-code`. Or copy the skill folder (.agents/skills/dsh-web-release in zhu1090093659/dsh-web) into .claude/skills/dsh-web-release in your project. Claude Code loads it when a task matches its description.
Run `npx skills add zhu1090093659/dsh-web --skill dsh-web-release -a codex`. Or copy the skill folder (.agents/skills/dsh-web-release in zhu1090093659/dsh-web) into .agents/skills/dsh-web-release in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhu1090093659/dsh-web --skill dsh-web-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dsh-web-release, .gemini/skills/dsh-web-release, .github/skills/dsh-web-release and .opencode/skills/dsh-web-release in your project.
Going by SKILL.md and its folder, Dsh Web Release needs the command-line tools its instructions call (git, pnpm, npm, node and gh) and credentials named NPM_TOKEN. Our summary lists: A credential in NPM_TOKEN.
SKILL.md contains no URLs. Its commands use git, npm and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Dsh Web Release is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dsh Web Release: Nx Run Tasks (nomcopter/react-mosaic, 4.8k stars), Migrate Internal Package into Ghost (TryGhost/Ghost, 56k stars), Open Code Review CLI (alibaba/open-code-review, 46k stars) and Cutting A Release (TriliumNext/Trilium, 38k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
zhu1090093659 (a GitHub user) maintains it in zhu1090093659/dsh-web, which has 8,608 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 10, 2026.
Source: zhu1090093659/dsh-web on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.