Dsh Workflow Isolate
Linxiushen/dsh-workflow-isolate · devops
QuickJS/WASM-isolated workflow engine for DeepSeek Harness with bounded resource controls.
★ 3GitHub stars
0Forks
2026-08-27Last updated
TypeScriptLanguage
MITLicense
Key features
- A fresh QuickJS runtime and realm are created for every workflow run.
- Invalid metadata, script size/V8 function-body syntax, provider routes, arguments, and policy overrides fail before a run is published.
- The guest receives only args, agent, parallel, pipeline, phase, and log
- no process, require, Node module loader, filesystem, network, or timers are injected.
- Only a plain-JSON projection crosses the guest boundary.
Requirements
- The current release targets @deepseek-ai/dsh-workflow@0.1.0-rc.7 and the associated DSH 0.1.0-rc.7 workflow packages.
- DSH's workflow API is still a release candidate, so compatibility is intentionally version-bounded.
Install command
dsh plugin --profile web add github:Linxiushen/dsh-workflow-isolate