Requirements
The plugin runs inside a DSH web profile and is not an independent npm application. The host supplies these peer dependencies:
@deepseek-ai/cordis
@deepseek-ai/dsh-client-runtime
@deepseek-ai/dsh-client-ui-slots
The documented target versions are DSH 0.0.1-rc.2+ (excluding 0.0.1-rc.1) and 0.1.0-rc.2+. After changes that cannot be hot-mounted, restart the web service with pnpm dsh web.
Configuration
| Setting |
Effect |
DSH_MARKET_OP_TIMEOUT_MS |
Operation timeout; defaults to 120000 ms |
DSH_MARKET_FETCH_TIMEOUT_MS |
pnpm fetch timeout override; the default is 30000 ms |
DSH_MARKET_FETCH_RETRIES |
Fetch retry count override; the default is 1 |
DSH_MARKET_FETCH_RETRY_MINTIMEOUT_MS |
Minimum retry backoff override |
DSH_MARKET_FETCH_RETRY_MAXTIMEOUT_MS |
Maximum retry backoff override |
With pnpm 11 or later, the profile’s pnpm-workspace.yaml may contain allowBuilds and minimumReleaseAgeExclude decisions. The plugin inherits these settings during web trial installation. A release younger than the default 24-hour minimumReleaseAge is automatically added to minimumReleaseAgeExclude and retried once.
How it behaves
The client is loaded through exports["./client"] and dsh.client, then registers the settings.plugins.tab slot. The host exposes catalogue, environment, installed-package, synchronisation and queue operations through /api/dsh-market. Catalogue data comes from plugins.json, then cached data, then data/catalog-snapshot.json.
Install, update and uninstall tasks run through a FIFO queue and spawn the dsh plugin CLI. Tasks can be cancelled or terminated, and retain pnpm logs. The plugin saves pre-operation copies as <profile>/.mkts-snapshot-<timestamp>.json. It can hot-mount simple web patches; otherwise changes take effect after restarting the relevant application.
Known limits
Curated installations accept listed github: sources; npm mappings are preferred when present. Non-web profiles do not receive trial boot validation. Cross-profile synchronisation only adds missing plugins and does not remove or downgrade existing ones. Same-origin checks apply to write requests.
Written from the project's own documentation and kept in sync with it. Where the two disagree, the source is authoritative — read the README on GitHub