← Back to home@LJH-snow

dsh-tool-dockerhub

No description

Stars
0
Language
TypeScript
Created
Oct 4, 2026
Updated
Oct 6, 2026

Introduction

dsh-tool-dockerhub

English | 中文

Read-only Docker Hub tools for DeepSeek Harness (dsh) as a Cordis plugin. Public search works without credentials; add a username + personal access token for private namespaces and authenticated rate-limit headers.

Install

npm install @libai168/dsh-tool-dockerhub

Requires @deepseek-ai/cordis (^4.0.1) and @deepseek-ai/dsh-tools (^0.1.0-rc.6) as peer dependencies.

Configuration

- name: 'github:LJH-snow/dsh-tool-dockerhub'
  config:
    # username: 'docker-user'
    # personalAccessToken: 'dckr_pat_...'
    # baseUrl: 'https://hub.docker.com'
    # timeoutMs: 15000

Create a personal access token in Docker Hub account settings. The token is exchanged for a short-lived JWT that stays in memory; it is never returned by any tool.

baseUrl is optional and must be an absolute http:// or https:// URL with a hostname. A reverse-proxy path prefix is allowed and trailing slashes are normalized. URL credentials, query strings, and fragments are rejected. Before every request, the final host is checked: localhost names, loopback/private/link-local/shared (CGNAT), multicast, and every IANA special-purpose block (reserved, documentation, benchmarking, the 2001::/23 IETF protocol assignments prefix, deprecated site-local, SRv6 SIDs, AS112, and IPv4-mapped/NAT64 forms) are blocked. Ordinary hostnames must resolve to only permitted public addresses; DNS failures, empty results, or mixed safe/unsafe results fail closed before fetch is called.

Tools

All tools are read-only.

ToolDescription
dockerhub_auth_testVerify username + PAT without exposing the token
dockerhub_get_namespaceReturn the configured namespace summary
dockerhub_list_repositoriesList repositories in a namespace with pagination and name filter
dockerhub_get_repositoryGet one repository by namespace/name
dockerhub_list_tagsList tags with digest, size, platform metadata
dockerhub_get_tagGet one tag's digest/size/platform details
dockerhub_search_repositoriesSearch public repositories (no credentials needed)
dockerhub_get_rate_limitsRead rate-limit response headers

Error contract

  • Missing credentials where required: { ok: false } / { found: false, reason }.
  • Docker Hub errors throw DockerHubError (status + code); tools surface them as normalized failure values.
  • page/pageSize are clamped server-side by the client (1-100).

Development

npm install
npm run typecheck
npm test
npm run build

License

MIT