
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
dsh-file-tree-panel
Advanced tools
DSH 文件树面板:在 Web 界面右侧栏显示当前工作文件夹的树形文件结构;子文件夹点击展开,文件点击在面板内预览内容(文本 / HTML 网页 / 图片 / 音频 / 视频 / PDF / 二进制)。
DSH(DeepSeek Harness)文件树面板插件:在 Web 界面右侧栏显示当前会话工作文件夹的树形文件结构。
dsh-file-tree-panel/
├── package.json # dsh.bundle.patch + dsh.client 声明 + exports(. / ./client / ./typert)
├── cordis.patch.yml # 插件组合层:挂载 fileTree 服务行(dsh plugin add 自动应用)
├── lib/
│ ├── index.js # 宿主插件:fileTree Remote 服务(fs 读取逻辑)
│ ├── typert.js # 宿主 TYPERT 清单(typert-loader 注册,网关校验用)
│ ├── schemas.js # 共享 zod 线格式
│ ├── remote-client.js # 客户端 Remote contribution(ctx.remote.$mount 挂载)
│ └── client.js # 客户端模块:details 栏 UI + 会话头部按钮
dsh.client 声明被发现并打进 Web bundle。dsh plugin --profile <name> add <pkg> 会在 profile 目录执行
pnpm add,并把声明了 dsh.bundle.patch 的包自动加入 dsh.profile.bundles
组合层(本包的 cordis.patch.yml 即该层,挂载 fileTree 服务行)。harness.handle / host.call 私有 RPC,宿主能力改走
typert Gateway:宿主注册 @Remote 服务(lib/index.js 用纯 JS 复刻装饰器),
客户端 ctx.remote.$mount(contribution) 挂载命名空间后调用
ctx.remote.fileTree.list({ path }) 等,两端由 zod 严格 codec 校验。官方生态的发布位置就是 npm 官方 registry(https://registry.npmjs.org/),
命名惯例为 dsh-* 或 @<scope>/dsh-*(参考 dsh-code、@dsh-feishu/dsh-feishu 等
社区包)。发布前请确认 lib/typert.js 的 TYPERT.package 与包名一致。
cd dsh-file-tree-panel
npm publish # 发布到 npm(或改用私有 registry / Git 仓库)
dsh plugin --profile web add dsh-file-tree-panel
该命令会:初始化 profile(如需要)→ 在 ~/.dsh/profiles/web 执行 pnpm add →
把本包自动加入 dsh.profile.bundles 组合层。之后重启 dsh(启动时
typert-loader 读取 exports["./typert"] 注册 fileTree 清单,clientModules 发现
dsh.client 包并重建客户端 bundle),打开页面(必要时强刷一次),右侧栏即出现
「📂 文件」面板——所有会话自动生效,无需任何手动改配置、创建或批准流程。
卸载:
dsh plugin --profile web remove dsh-file-tree-panel查看:dsh plugin --profile web list/dsh plugin --profile web why dsh-file-tree-panel手动安装(不经过dsh plugin时):pnpm add到 profile + 在cordis.patch.yml加一行- id: file-tree-panel/name: dsh-file-tree-panel,效果相同。
useSessions 快照的 cwd,
缺失时回退到 sandboxPolicy.workspaceRoot)。| 现象 | 原因 / 处理 |
|---|---|
启动报 Cannot find package 'dsh-file-tree-panel' | 包没装进 ~/.dsh/profiles/web 的依赖,重跑 pnpm add |
报 TYPERT manifest names package ... | lib/typert.js 的 package 字段与包名不一致(改名发布时记得同步) |
| 页面没有右侧栏 | 重启后 bundle 未重建:清缓存强刷;确认组合行已加且无 disabled |
| 面板出现但树为空 / 报错 | 检查宿主日志中 fileTree 服务是否注册(service "fileTree" 相关报错多为清单未加载) |
| 预览 HTML 空白 | 文件内引用的相对资源(图片/CSS/JS 文件)在 data URL 下无法加载——单文件 HTML 正常 |
| 动态插件(cordis_define) | 静态包(本仓库) |
|---|---|
harness.handle('fs-list', ...) | FileTreeService.list() + @Remote 标记 |
host.call('fs-list', { path }) | ctx.remote.fileTree.list({ path }) |
Client styles.insert(css) 内置 | 受控 <style> 注入(ensureStyles()) |
| 每次会话需 define + 批准 | 组合行安装后永久生效 |
FAQs
DSH 文件树面板:在 Web 界面右侧栏显示当前工作文件夹的树形文件结构;子文件夹点击展开,文件点击在面板内预览内容(文本 / HTML 网页 / 图片 / 音频 / 视频 / PDF / 二进制)。
The npm package dsh-file-tree-panel receives a total of 25 weekly downloads. As such, dsh-file-tree-panel popularity was classified as not popular.
We found that dsh-file-tree-panel demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.