2026-08-06 04:39:52 +08:00
{
2026-08-13 00:36:22 +08:00
"name" : "@deepseek-ai/dsh-host-frontend-static" ,
2026-08-20 15:07:39 +08:00
"description" : "SPA dist server for the Web shell: owns the webserver fallback seat, serving explicit index entries and static assets with traversal rejection and 404 misses" ,
2026-08-21 19:48:58 +08:00
"version" : "0.1.1-rc.2" ,
2026-08-11 00:02:53 +08:00
"publishConfig" : {
2026-08-13 18:05:10 +08:00
"access" : "public"
2026-08-11 00:02:53 +08:00
} ,
"repository" : {
"type" : "git" ,
"url" : "git+https://github.com/deepseek-ai/deepseek-harness.git" ,
"directory" : "packages/host/frontend-static"
} ,
2026-08-06 04:39:52 +08:00
"type" : "module" ,
"main" : "lib/index.js" ,
"types" : "lib/types/index.d.ts" ,
"exports" : {
"." : {
"types" : "./lib/types/index.d.ts" ,
"default" : "./lib/index.js"
} ,
"./invariant" : {
"types" : "./lib/types/invariant.d.ts" ,
"default" : "./lib/invariant.js"
} ,
"./src/*" : "./src/*" ,
"./package.json" : "./package.json"
} ,
"files" : [
"lib/index.js" ,
"lib/invariant.js" ,
"lib/types/**/*.d.ts"
] ,
2026-08-13 01:46:57 +08:00
"license" : "MIT" ,
2026-08-06 04:39:52 +08:00
"peerDependencies" : {
2026-08-11 00:16:45 +08:00
"@deepseek-ai/dsh-host-webserver" : "workspace:^" ,
"@deepseek-ai/dsh-invariants" : "workspace:^" ,
"@deepseek-ai/cordis" : "workspace:^"
2026-08-06 04:39:52 +08:00
} ,
"dependencies" : {
2026-08-11 00:16:45 +08:00
"@deepseek-ai/schemastery" : "workspace:^"
2026-08-06 04:39:52 +08:00
} ,
"devDependencies" : {
build(vendor): rescope the vendored Cordis packages into @deepseek-ai
Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it
prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`,
`verify-translation-pairing --write` for the touched bilingual pairs,
`gen-doc-graphs`, and one typert snapshot whose ids embed character offsets.
`pnpm run rescope-vendor --check` verifies the result.
Renames nine vendored packages (cordis, cosmokit, schemastery and the six
@cordisjs plugins) and every reference that resolves them: manifest names and
dependency keys, module specifiers including declare-module merges, cordis.yml
plugin names, tsconfig paths, every Markdown fence, and `docs/` prose.
Directory names, upstream versions, and dependency ranges are unchanged, so
vendor/README.md still reads as an upstream snapshot; its manifest table gains
an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed
at each fork's origin.
The tutorial tier follows the rename end to end: its yaml fences named plugins
the Loader can no longer resolve, its `ts ignore-check` fences disagreed with
the compiled fences beside them, and its prose quoted both. The contracts that
told readers to keep upstream names — the root convention and the vendoring
cookbook's tree comment and manifest invariant — now say to rescope instead.
Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle
purity gate now names the vendored libraries a browser bundle inlines, and the
files where a bare `cordis` is an agent-preset id keep that product data.
2026-08-10 22:04:06 +08:00
"@deepseek-ai/cordis-plugin-loader" : "workspace:^" ,
2026-08-06 04:39:52 +08:00
"@deepseek-ai/dsh-host-webserver" : "workspace:^" ,
"@deepseek-ai/dsh-invariants" : "workspace:^" ,
2026-08-11 00:16:45 +08:00
"@deepseek-ai/cordis" : "workspace:^"
2026-08-06 04:39:52 +08:00
}
}