{"_id":"@becomeopc/dshx-plugin-marketplace","name":"@becomeopc/dshx-plugin-marketplace","dist-tags":{"preview":"0.1.0-preview.0","latest":"0.1.0-preview.0"},"versions":{"0.1.0-preview.0":{"name":"@becomeopc/dshx-plugin-marketplace","version":"0.1.0-preview.0","description":"A self-hosted Framework Hub marketplace for DSH profiles.","keywords":["deepseek","deepseek-harness","dsh","plugins","marketplace"],"license":"MIT","engines":{"node":"^22.19.0 || >=24.0.0"},"repository":{"type":"git","url":"git+https://github.com/liyown/dshx.git","directory":"packages/plugin-marketplace"},"bugs":{"url":"https://github.com/liyown/dshx/issues"},"homepage":"https://dshx.io/plugins/dshx-plugin-marketplace","publishConfig":{"access":"public"},"type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./client":{"types":"./dist/client.d.ts","default":"./dist/client.js"},"./cordis.patch.yml":"./cordis.patch.yml","./package.json":"./package.json"},"dsh":{"bundle":{"patch":"./cordis.patch.yml"},"client":{"platform":"web","inject":["@deepseek-ai/dsh-client-connection","@deepseek-ai/dsh-client-ui-settings","@deepseek-ai/dsh-client-locale","@deepseek-ai/dsh-client-ui-primitives"],"external":[],"immediately":false}},"dependencies":{"execa":"10.0.1","semver":"7.8.5","zod":"4.4.3"},"devDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh":"0.1.0-rc.8","@deepseek-ai/dsh-app-boot":"0.1.0-rc.8","@deepseek-ai/dsh-client-connection":"0.1.0-rc.8","@deepseek-ai/dsh-client-locale":"0.1.0-rc.8","@deepseek-ai/dsh-client-ui-primitives":"0.1.0-rc.8","@deepseek-ai/dsh-client-ui-settings":"0.1.0-rc.8","@deepseek-ai/dsh-client-ui-slots":"0.1.0-rc.8","@deepseek-ai/dsh-cordis-host-runner":"0.1.0-rc.8","@deepseek-ai/dsh-settings":"0.1.0-rc.8","@deepseek-ai/dsh-tool-cordis":"0.1.0-rc.8","@deepseek-ai/dsh-tools":"0.1.0-rc.8","@deepseek-ai/schemastery":"3.18.1","@testing-library/dom":"^10.4.1","@testing-library/react":"^16.1.0","@types/node":"22.19.20","@types/react":"~18.3.31","@types/react-dom":"~18.3.7","@types/semver":"^7.7.1","jsdom":"^26.1.0","react":"^18.3.1","react-dom":"^18.3.1","typescript":"5.9.3","vitest":"4.1.11","@becomeopc/dshx":"0.1.4-preview.0"},"peerDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh":">=0.1.0-rc.8 <0.2.0-0 || 0.1.1-rc.2","@deepseek-ai/dsh-app-boot":">=0.1.0-rc.8 <0.2.0-0 || 0.1.1-rc.2","@deepseek-ai/dsh-client-connection":">=0.1.0-rc.8 <0.2.0-0 || 0.1.1-rc.2","@deepseek-ai/dsh-client-locale":">=0.1.0-rc.8 <0.2.0-0 || 0.1.1-rc.2","@deepseek-ai/dsh-client-ui-primitives":">=0.1.0-rc.8 <0.2.0-0 || 0.1.1-rc.2","@deepseek-ai/dsh-client-ui-settings":">=0.1.0-rc.8 <0.2.0-0 || 0.1.1-rc.2","@deepseek-ai/dsh-settings":">=0.1.0-rc.8 <0.2.0-0 || 0.1.1-rc.2","@deepseek-ai/dsh-tools":">=0.1.0-rc.8 <0.2.0-0 || 0.1.1-rc.2","@deepseek-ai/schemastery":"^3.18.1","react":">=18 <20"},"scripts":{"check":"pnpm --filter @becomeopc/dshx build && node ../dshx/dist/cli/bin.js check","typecheck":"tsc --noEmit","test":"vitest run","build":"pnpm --filter @becomeopc/dshx build && node ../dshx/dist/cli/bin.js build","dev":"pnpm --filter @becomeopc/dshx build && node ../dshx/dist/cli/bin.js dev --open"},"_id":"@becomeopc/dshx-plugin-marketplace@0.1.0-preview.0","_integrity":"sha512-GUXSoJtHKtcQk7JvmpjU/TKRBJBcKhnTqS+XUDeZ2NMfffYpj3zjm1CrrWDJEqLT4KJpZn8wNwNjGMHNxM7QOA==","_resolved":"/private/var/folders/0r/smxslb8510q54nfy8zpdhnj00000gn/T/38019d0125575176a21aa0e291c53298/becomeopc-dshx-plugin-marketplace-0.1.0-preview.0.tgz","_from":"file:becomeopc-dshx-plugin-marketplace-0.1.0-preview.0.tgz","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-GUXSoJtHKtcQk7JvmpjU/TKRBJBcKhnTqS+XUDeZ2NMfffYpj3zjm1CrrWDJEqLT4KJpZn8wNwNjGMHNxM7QOA==","shasum":"5f41d511c06c136d53bcc24366517ab0674d29c5","tarball":"https://registry.npmjs.org/@becomeopc/dshx-plugin-marketplace/-/dshx-plugin-marketplace-0.1.0-preview.0.tgz","fileCount":10,"unpackedSize":864226,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIBkXxsFpMYql5s/CgZevYktF0a6XqV5qZ2SXSGJITnZwAiEAwMdhs82S1HQCoQ8eih4JvibMkVFG2I0W+8r3vUsxgTQ="}]},"_npmUser":{"name":"becomeopc","email":"liuyaowen.smile@gmail.com"},"directories":{},"maintainers":[{"name":"becomeopc","email":"liuyaowen.smile@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dshx-plugin-marketplace_0.1.0-preview.0_1787739969192_0.5254107947586311"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-26T10:26:08.869Z","0.1.0-preview.0":"2026-08-26T10:26:09.390Z","modified":"2026-08-26T10:26:09.719Z"},"maintainers":[{"name":"becomeopc","email":"liuyaowen.smile@gmail.com"}],"description":"A self-hosted Framework Hub marketplace for DSH profiles.","homepage":"https://dshx.io/plugins/dshx-plugin-marketplace","keywords":["deepseek","deepseek-harness","dsh","plugins","marketplace"],"repository":{"type":"git","url":"git+https://github.com/liyown/dshx.git","directory":"packages/plugin-marketplace"},"bugs":{"url":"https://github.com/liyown/dshx/issues"},"license":"MIT","readme":"# DSHX Plugin Marketplace\n\n`@becomeopc/dshx-plugin-marketplace` is DSHX's self-hosting reference plugin. It adds **Settings → Plugins → Marketplace** to a DSH Web Profile and reads Framework Hub's installable marketplace catalog.\n\nThe package exercises the complete plugin authoring path produced by `create-dshx`: `defineHost`, `defineSettings`, `defineApi`, `defineClient`, `defineLocale`, `defineSlot`, Standard Schema validation, and `useApiQuery`. It is built and installed as an ordinary DSH bundle; no Harness or DSHX core patch is required.\n\n## Develop and build\n\nFrom the DSHX workspace:\n\n```sh\npnpm install\npnpm --filter @becomeopc/dshx-plugin-marketplace check\npnpm --filter @becomeopc/dshx-plugin-marketplace typecheck\npnpm --filter @becomeopc/dshx-plugin-marketplace test\npnpm --filter @becomeopc/dshx-plugin-marketplace build\n```\n\nRun `pnpm --filter @becomeopc/dshx-plugin-marketplace dev` to start the real DSH development Profile. Client changes use official HMR; Host changes rebuild and restart the Host process. Add `-- --port 0` when the default Web port is occupied.\n\n## Install\n\nThe Preview package is installed into the Profile that should own the marketplace:\n\n```sh\ndsh plugin --profile web add @becomeopc/dshx-plugin-marketplace@preview\ndsh --profile web\n```\n\nFor an unpublished workspace build, run `pnpm --filter @becomeopc/dshx-plugin-marketplace pack`, then pass the emitted `.tgz` path to the same `dsh plugin --profile web add` command.\n\nInstalled plugins become active after the Profile is restarted. The first version intentionally does not restart DSH automatically.\n\n## Framework Hub configuration\n\nThe settings namespace is `dshx-plugin-marketplace`:\n\n```yaml\ndshx-plugin-marketplace:\n  hubBaseUrl: https://dshx.io\n```\n\nThe value updates live. Production endpoints must use HTTPS; loopback HTTP is accepted only for local development and smoke tests.\n\nThe Host reads `GET /api/marketplace/plugins` and `GET /api/marketplace/plugins/:slug`. Those endpoints are separate from Hub's discovery/SEO catalog. An install always re-fetches the exact detail and accepts only one active primary target whose package and version match the published catalog entry. The client does not submit a package name, version, or command.\n\n## Security boundary\n\n- The browser submits only a Hub slug. The Host fetches the plugin detail again and accepts exactly one active primary install target.\n- Compatibility is checked against the running DSH version before installation.\n- The DSH CLI is invoked with a fixed argument array, without a shell, with cancellation, a five-minute timeout, and one install task per Profile process.\n- Host responses are validated before display. Local paths and raw terminal output remain in Host logs.\n- Community plugins display an additional third-party code warning before installation.\n\nThis Preview contains categories, compact cards, pagination, installation, and restart guidance. It does not contain search, sorting controls, ratings, details, uninstall, update, hot loading, or automatic restart. Installation works only from a loopback DSH Web session because the typed Host API is intentionally loopback-only.\n","readmeFilename":"README.md","_rev":"1-3354163c42a0cbbacb4b54e6f8069e9f"}