xxiaoxiong/dsh-issue-tracker
dsh-issue-tracker
Listed
1
Tools
Bundle verified
What it does
Jira Cloud issue-tracker integration exposing eight model tools for issue search, project and transition lookup, creation, updates, comments, and transitions; writes are opt-in and support dry-run.
Best for
- Teams managing Jira Cloud issues directly through DeepSeek Harness.
- Read-oriented workflows for issue search, project discovery, and transition lookup.
- Controlled Jira creation, updates, comments, and transitions using opt-in writes and dry runs.
Not ideal for
- Issue trackers other than Jira Cloud REST API v3.
- Environments without a Jira base URL and supported API or bearer credentials.
- Unattended write automation that cannot explicitly enable writes or use dry-run safeguards.
- Runtimes outside Node.js `^22.19.0 || >=24.0.0` or the documented Harness version.
README
dsh-issue-tracker
Jira Cloud issue-tracker service and model-facing tools for DeepSeek Harness.
The package is one installable DSH bundle with three internal roles:
- a provider-neutral Cordis
issueTrackerservice; - a Jira Cloud REST API v3 provider;
- eight tools registered through the public DSH
ToolRuntimeservice.
The plugin is read-only by default. Create, update, comment, and transition
operations require an explicit writeEnabled: true; every write tool also
supports a side-effect-free dryRun.
Requirements
- Node.js
^22.19.0 || >=24.0.0 - DeepSeek Harness
0.1.0-rc.6 - Jira Cloud REST API v3
Install
dsh plugin --profile web add dsh-issue-tracker
The bundle row stays disabled until these variables are available:
$env:JIRA_BASE_URL = 'https://your-domain.atlassian.net'
$env:JIRA_EMAIL = 'you@example.com'
$env:JIRA_API_TOKEN = 'your-api-token'
Writes remain disabled. Enable them only when intended:
$env:DSH_ISSUE_TRACKER_WRITE_ENABLED = 'true'
Restart DSH, then inspect the composed row:
dsh --profile web --dump-config
For OAuth bearer authentication or non-environment configuration, replace the
issue-tracker row in the profile’s cordis.patch.yml; a patch replaces the
whole row, so restate every field:
- id: issue-tracker
name: dsh-issue-tracker
config:
baseUrl: https://your-domain.atlassian.net
auth:
type: bearer
accessToken: !!js process.env.JIRA_ACCESS_TOKEN
writeEnabled: false
Tools
| Tool | Purpose | Writes |
|---|---|---|
issue_get |
Read one issue | No |
issue_search |
Search with filters or raw JQL | No |
issue_transitions |
List available transitions | No |
issue_projects |
List visible projects | No |
issue_create |
Create an issue | Yes |
issue_update |
Update issue fields | Yes |
issue_comment |
Add a comment | Yes |
issue_transition |
Apply a transition | Yes |
All HTTP calls honor the DSH tool cancellation signal and a configured request
deadline. Structured filters are JQL-escaped; providerQuery is intentionally
raw JQL and should be governed like any other privileged query input.
Security
- HTTPS is required unless
allowInsecureHttp: trueis explicitly set. - Credentials in
baseUrlare rejected. - Secrets are marked with Schemastery’s secret role.
- The plugin does not log credentials, prompts, issue bodies, or comments.
- No telemetry is collected or sent by this package.
See docs/security.md for the complete boundary.
Uninstall
dsh plugin --profile web remove dsh-issue-tracker
Cordis owns both the service registration and tool registrations, so unloading
the bundle removes all eight tools and the issueTracker service.
Verification status
The release is typechecked and tested on Windows with real Cordis and DSH
0.1.0-rc.6 packages. HTTP behavior is tested with mocked Jira responses; no
live Jira tenant or production credential was used. See
docs/verification-report.md.
中文说明
这是一个面向 DeepSeek Harness 的 Jira Cloud 工单插件。安装一个 npm 包即可
获得通用 issueTracker 服务和 8 个模型工具。插件默认只读;所有写操作必须显式
开启 writeEnabled,并且可以先用 dryRun 验证参数而不产生副作用。
许可证:MIT。
Frequently Asked QuestionsFAQ
Use the verified command dsh plugin --profile default add github:xxiaoxiong/dsh-issue-tracker in a DSH-enabled shell. The command resolves the public package metadata and keeps the plugin attached to the catalog identity shown on this page.
Compatibility follows the bundle and profile status shown above. If a profile is not detected, keep the plugin disabled there and check the repository documentation before enabling it in production.
The GitHub link and activity metadata are the source of truth for releases and maintenance. Revisit this page after a new release to confirm the catalog has observed the latest version.