makecindy / makecindy/cindy

DSH: supply-chain-verified runtime and scoped bridge supervisor

Open
#3,773 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
2.7k
Forks
395
Avg merge
21h 48m
Merged PRs (30d)
776

Description

## 目标

在 Desktop Main 建立受管 DSH runtime 和 Cindy scope supervisor;它拥有 DSH_HOME、受限环境、进程与有界 teardown。

## 交付

- reviewed wheel pin、hash/tree/sidecar 验证和 optional agent-binary registration。
- Main-only `DshHostManager` / scope registry、非项目 launcher cwd、managed Home、env allowlist、health 与 quit cleanup。
- 没有 PATH、npm、pnpm、pip、curl 或系统 Node fallback。

## 验收

- 缺失/损坏/不支持平台仅让该 DSH scope unavailable。
- Renderer/Mobile 不得到 executable、Home、ACP transport 或 secret。

Blocked by #3772. Blocks #3774.

Canonical plan: `docs/issues/dsh-native-integration/`.

Contributor guide

Open the contributing guide

Research direction

Start with the canonical plan in docs/issues/dsh-native-integration/ and review blocker #3772. Then map the Desktop Main DshHostManager and scope registry requirements, including managed home, environment allowlist, health checks, and quit cleanup. Done means the stated delivery and acceptance conditions hold, including isolation from Renderer/Mobile and scope-only unavailability for unsupported runtimes.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
desktop, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.