xxiaoxiong/dsh-ci
dsh-ci
Listed
1
Workflow
Bundle verified
What it does
Provider-neutral CI/CD capability for DeepSeek Harness with GitHub Actions support, bounded failure evidence, source-aware diagnostics, and approval-gated rerun/cancel controls.
Best for
- Developers diagnosing GitHub Actions failures from bounded, source-linked evidence.
- Agents checking workflow, job, step, and artifact status without parsing raw CLI output.
- Teams that want secret-redacted CI logs and approval-gated rerun or cancel operations.
Not ideal for
- GitLab CI, Jenkins, CircleCI, or other providers not implemented in the current version.
- Investigations that require complete unbounded logs; returned evidence is size-limited and error-focused.
- Automation that must rerun or cancel pipelines without write enablement and user approval.
- Repositories that cannot be mapped to GitHub or accessed with available GitHub credentials.
README
dsh-ci - Continuous Integration (CI) plugin for DeepSeek Harness (DSH)
dsh-ci is a generic, provider-neutral CI/CD plugin for DeepSeek Harness (DSH). It enables agents to inspect CI runs, extract bounded failure evidence, locate source errors, and safely rerun or cancel pipelines.
The current version supports GitHub Actions as the primary CI provider. Its architecture is explicitly designed to be provider-neutral, allowing future implementations for GitLab CI, Jenkins, CircleCI, etc. without modifying the generic CI tool layer.
Architecture
DSH Agent
↓
Generic CI Tools (ci_status, ci_failure, etc.)
↓
ctx.ci (CIService Context interface)
↓
GitHubActionsProvider (implements CIService)
↓
GitHub Actions REST API
Key Features
- Generic CI Tools: A stable set of 9 tools exposed to the agent loop.
-
Ecosystem-neutral Service Layer: Abstract
CIServiceandAbstractCIProvidercore contracts. - Automatic Workspace Detection: Parses local git repository (origins, remotes, branches, HEAD) to automatically map owner and repository without user input.
- Failure evidence extraction: Bounded logs (default 8KB), error-focused extraction (only lines around errors), and de-duplication.
-
Failure Parser Registry: Specialized regex parser patterns to map compile errors, test suite failures, docker fails, and generic exit codes to exact source files, lines, and functions. Supports:
- TypeScript compilation errors (
tsc) - Jest / Vitest test runner failures
- pytest (Python) failures
- Maven / Gradle (Java) build failures
- Go test failures
- Cargo (Rust) compile errors
- ESLint errors
- Docker build errors
- npm install/dependency errors
- Generic command exit codes
- TypeScript compilation errors (
- Secret Redaction: Automatic scrubbing of sensitive tokens, private keys, passwords, and AWS keys from all log output returned to the LLM.
-
Write Approval Gates: Write operations (
ci_rerun,ci_cancel) are approval-gated and disabled by default (writeEnabled: false). Cancel operation always requires approval.
Installation
Add this plugin directly via DeepSeek Harness CLI:
dsh plugin add dsh-ci
Configuration
Add the following block to your settings.json or settings.local.json configuration file:
{
"plugins": {
"dsh-ci": {
"writeEnabled": false,
"maxLogSize": 8192,
"maxEvidenceItems": 50,
"apiBase": "https://api.github.com"
}
}
}
Credentials
The plugin integrates with the standard DSH credential manager. It will automatically check for credentials in the following order:
-
GH_TOKENenvironment variable -
GITHUB_TOKENenvironment variable - Local
ghauth credentials (via GitHub CLI helper)
Tool Reference
The plugin registers 9 provider-neutral tools inside DSH:
ci_status
Gets the overall CI status of the repository, current branch, or commit.
-
Parameters:
repository?,branch?,commit?
ci_runs
Lists recent workflow runs in the repository.
-
Parameters:
repository?,branch?,status?,limit?
ci_run
Retrieves a detailed description of a single run.
-
Parameters:
runId(required),repository?
ci_jobs
Lists all jobs and their execution steps inside a workflow run.
-
Parameters:
runId(required),repository?
ci_failure
Looks up a failed run, identifies the failing jobs/steps, parses their logs, and compiles a structured failure evidence block containing exact file paths, line numbers, test names, and a bounded log excerpt.
-
Parameters:
runId(required),jobId?,repository?,maxExcerpts?
ci_log
Fetches log excerpts for a given job or step. Excerpts are bounded in size and redact all secrets automatically.
-
Parameters:
jobId(required),stepId?,repository?,maxBytes?
ci_artifacts
Lists metadata about build artifacts.
-
Parameters:
runId(required),repository?
ci_rerun
Triggers a rerun of a workflow run. Requires write authorization.
-
Parameters:
runId(required),dryRun?,repository?
ci_cancel
Cancels an in-progress workflow run. Always requires approval.
-
Parameters:
runId(required),repository?
Security Model
- Untrusted Input: All log outputs are treated as untrusted data. We filter and redact strings matching high-risk signatures (e.g., token prefixes, private keys) to prevent prompt injection and credential leaking.
- Context Preservation: Full logs are never returned to the model. We slice logs to focus on errors, avoiding context window explosion.
- Approval Flow: Triggering runs or cancels will prompt the user with DSH Approval seam for explicit consent before issuing the REST requests.
License
MIT License.
Frequently Asked QuestionsFAQ
Use the verified command dsh plugin --profile default add github:xxiaoxiong/dsh-ci in a DSH-enabled shell. The command resolves the public package metadata and keeps the plugin attached to the catalog identity shown on this page.
Compatibility follows the bundle and profile status shown above. If a profile is not detected, keep the plugin disabled there and check the repository documentation before enabling it in production.
The GitHub link and activity metadata are the source of truth for releases and maintenance. Revisit this page after a new release to confirm the catalog has observed the latest version.