dsh-git-plugin
A visual Git workbench for DeepSeek Harness Web—inspect repositories, run common Git actions, and safely execute AI-generated workflows.
- Stars
- 5
- Language
- JavaScript
- Created
- Aug 14, 2026
- Updated
- Sep 18, 2026
Introduction
DSH Git Plugin
A visual Git workbench for inspecting repositories, running common actions, and safely executing AI-generated Git workflows in DeepSeek Harness Web.
English · 简体中文
How to use
👀 Inspect Git state → 🖱️ Run a quick action or ask the Agent → ✅ Review → 🚀 Execute
Preview

Features
- Visual repository state: See the current branch, staged and unstaged files, and each file's formatted review view or raw diff.
- Commit history and details: Browse the current branch as a commit graph, then click a commit to inspect its message, author, timestamps, parents, changed files, statistics, and full diff.
- One-click Git actions: Stage or unstage one file or all files, create commits, and create, search, switch, or safely delete local branches directly from the workbench.
- Remote sync and Rebase: Inspect upstream, ahead/behind counts, and working-tree state; fetch, fast-forward pull, push, set an upstream for a new branch, or safely start, continue, and abort a Rebase.
- References at a glance: Inspect local branches, remote branches, and tags without leaving DeepSeek Harness Web.
- Natural-language workflows: Turn a request into a clear, step-by-step Git command proposal, then execute it directly or copy it for manual execution.
- Actionable failure handling: Keep the failed command, output, and post-failure repository diagnostics together; offer a safe recovery proposal for recognized failures or let the Agent analyze a complex failure.
- Safety by default: Validate commands against a conservative allowlist, require confirmation for high-risk operations and history rewrites, prevent proposal replay, and redact common credentials from diagnostics.
Quick start
0. Allow immediate installation of the new package
Newer versions of pnpm may delay recently published packages. To install the latest release immediately, add dsh-easygit-plugin to ~/.dsh/profiles/web/pnpm-workspace.yaml:
minimumReleaseAgeExclude:
- dsh-easygit-plugin
1. Install the plugin
dsh plugin --profile web add dsh-easygit-plugin
2. Start DSH Web
dsh web
3. Open the Git workbench
Use the Git button beside the composer to inspect changes, review commit history, stage files, commit changes, manage branches, or synchronize with a remote. Rebase and forceful branch deletion require an explicit risk confirmation.
Conflict resolution
Open Git workbench → 冲突解决 (Conflict resolution), also linked from Changes and Sync:
- Inspect conflicted files and the active Merge / Rebase / Cherry-pick operation, or start an operation using a branch or commit reference.
- Compare three panes: current side, incoming side, and editable result, with commit references and short SHAs identifying the two sides. Each pane shows its own line numbers; result numbers track editing and scrolling and highlight unresolved conflicts. Each block shows its result line range and count (including markers). Accept either side, keep both with the current side first, edit manually, or jump to the next block.
- Save the result to the working tree, then mark it resolved to stage it. Remaining conflict markers block resolution; external file or operation changes invalidate the snapshot instead of silently overwriting new content.
- Continue after all files are resolved. Further conflicts refresh the list. Explicit confirmation also enables abort, or skipping the current Rebase / Cherry-pick commit, including empty commits.
The incoming side is the actual conflict source for this operation, not necessarily the current branch’s remote upstream. During Rebase, the current side is the target branch plus replayed commits; the incoming side is the commit being replayed. Delete/modify conflicts offer explicit deletion. Binary and non-UTF-8 conflicts offer whole-side selection. Text editing supports up to 48 KiB per version; use external tools for larger files, symlinks, and submodules, then refresh.
Unsaved edits block tab switching and retain a draft for the current page lifetime. Browser reload warns before losing edits, but drafts do not persist across reloads. Authenticated session actions read the content; file writes and Git commands run through Harness Shell with the session sandbox policy.
After upgrading the local plugin, restart the Harness backend and refresh the browser so both Host and Client load the new build.
Conflict-resolution validation: all 92 tests and 27 reproducible build artifacts passed, covering base/side reads, three-pane display and commit sources, dynamic line numbers and conflict ranges, block choices, save/resolve, successive Rebase conflicts, empty-commit skipping, linked worktrees, stale snapshots, and session isolation. Full Merge, Rebase, and Cherry-pick browser workflows were verified using an isolated temporary Harness instance and real Git repositories, including block choices, manual edits, whole-side selection, saving, resolving, and continuing. Regression coverage also includes valid separator lines, unborn repositories, and special filenames.
For a more involved workflow, ask the Agent for a Git operation. For example:
Commit the documentation update to the current branch with the message "docs: update guide"
Review the generated steps in the Git workbench, then choose direct execution or manual execution.
Install from source
git clone https://github.com/IT-coder-Yy/dsh-git-plugin.git
cd dsh-git-plugin
npm install
npm run build
dsh plugin --profile web add ${PWD}
Install from GitHub repository
dsh plugin --profile web add github:IT-coder-Yy/dsh-git-plugin
Update the plugin
dsh plugin --profile web update dsh-easygit-plugin
Uninstall the plugin
dsh plugin --profile web remove dsh-easygit-plugin
How it works
The plugin registers two model tools:
| Tool | Description |
|---|---|
git_repo_state | Reads the current repository state without modifying it. |
git_propose | Validates and registers one or more Git steps. |
The Web profile adds a Git action beside the composer and opens the workbench in a native right-sidebar tab. Its tabs provide visual access to working-tree changes and diffs, branches and references, commit history and details, stashes, remote synchronization, and Agent-generated proposals. Commands are validated both when a proposal is created and immediately before execution. When an action fails, the workbench preserves structured error context and repository diagnostics; recognized failures can create a new recovery proposal, while complex failures can be handed back to the Agent for analysis.
Security
- Each step must contain exactly one allowed
git <subcommand> ...command. - Shell control operators, command substitution, redirection, executable hooks, and unsafe Git options are rejected.
- High-risk operations, including history rewrites, require explicit confirmation and proposals can only be executed once.
- The plugin follows the Shell and sandbox policies provided by DeepSeek Harness; use it only with trusted repositories and trusted Git configuration.
Please report vulnerabilities privately by following SECURITY.md.
Compatibility
Last verified on 2026-09-18 with DeepSeek Harness 0.1.6-alpha.2 and dsh-easygit-plugin 0.3.0, against upstream commit ddefc45. Web startup, native tab registration, and repository inspection were also checked on 0.1.5-rc.2. The 0.3.x plugin uses the new sidebar and session APIs and no longer targets 0.1.0-rc.8.
The adaptation uses native sidebar tabs (DSH owns sizing, splitting, and closing), session-scoped Agent analysis, repository access for sessions without a running Agent and persisted sessions, and DSH Connection browser authentication and origin checks. Persisted sandbox modes are preserved; unknown sessions never fall back to an arbitrary directory.
Validation covered npm run check (72 tests and 24 reproducible build artifacts), a dry-run npm package, and browser checks on 0.1.6-alpha.2 for repository inspection, diffs, staging, committing, and native tab operations. Git integration tests use temporary repositories and cover branches, stashes, fetch/pull/push, successful and conflicted Rebases, recovery, and proposal safety. Live model-generated replies were not exercised.
Install the official package matching that source version without building DSH yourself:
npm install -g @deepseek-ai/dsh@0.1.6-alpha.2
Back up the DSH installation and Web profile before upgrading, and check other third-party plugins for compatibility. Older plugins may reference removed settings APIs and prevent the entire profile from starting.
Development
Requires Node.js ^22.19.0 || >=24.0.0, Git, and a DeepSeek Harness developer preview release that supports static Cordis plugins.
npm install
npm run check
npm pack --dry-run --ignore-scripts