
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
dsh-model-accordion
Advanced tools
Provider-folded model selector for the DSH Web composer with catalog-driven reasoning effort choices.
Provider-folded model selector for the DeepSeek Harness Web composer.
识图镜像(带图会话) section when those providers are present.0.1.0-rc.8 or newer.This is a Web UI plugin. It does not add a Host service, model provider, vision backend, or model catalog. Provider availability and image-session admission remain controlled by DSH and any installed provider/vision plugins.
dsh plugin --profile web add dsh-model-accordion
For a local checkout during development:
dsh plugin --profile web add file:/absolute/path/to/dsh-model-accordion
Refresh the Web UI after installation. The package declares a dsh.bundle patch and a Web client entry, so it is installed and loaded as a persistent profile bundle rather than a temporary runtime extension.
识图镜像(带图会话) section is shown when provider names identify vision-router mirror routes. It is kept collapsed to avoid duplicating every provider in the main list.node --check lib/client.js
node --check lib/index.js
npm pack --dry-run --ignore-scripts
MIT
FAQs
Provider-folded model selector for the DSH Web composer with catalog-driven reasoning effort choices.
We found that dsh-model-accordion demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.