DSH: supply-chain-verified runtime and scoped bridge supervisor
- Dominant language
- TypeScript
- Stars
- 2.7k
- Forks
- 395
- Avg merge
- 21h 48m
- Merged PRs (30d)
- 776
Description
## 目标
在 Desktop Main 建立受管 DSH runtime 和 Cindy scope supervisor;它拥有 DSH_HOME、受限环境、进程与有界 teardown。
## 交付
- reviewed wheel pin、hash/tree/sidecar 验证和 optional agent-binary registration。
- Main-only `DshHostManager` / scope registry、非项目 launcher cwd、managed Home、env allowlist、health 与 quit cleanup。
- 没有 PATH、npm、pnpm、pip、curl 或系统 Node fallback。
## 验收
- 缺失/损坏/不支持平台仅让该 DSH scope unavailable。
- Renderer/Mobile 不得到 executable、Home、ACP transport 或 secret。
Blocked by #3772. Blocks #3774.
Canonical plan: `docs/issues/dsh-native-integration/`.
Contributor guide
Research direction
Start with the canonical plan in docs/issues/dsh-native-integration/ and review blocker #3772. Then map the Desktop Main DshHostManager and scope registry requirements, including managed home, environment allowlist, health checks, and quit cleanup. Done means the stated delivery and acceptance conditions hold, including isolation from Renderer/Mobile and scope-only unavailability for unsupported runtimes.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- desktop, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100