On-demand GitHub proxy for the Web UI: one-click git/SSH proxy toggle with connectivity tests.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:wjt0321/dsh-git-proxy
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
dsh-git-proxy
On-demand GitHub proxy for DeepSeek Harness. Toggle the git/SSH proxy for github.com from the Web UI settings, save your proxy address, and test connectivity before downloading.
Install
From the plugin market, or:
dsh plugin --profile web add github:wjt0321/dsh-git-proxy
Restart the Web UI, then open Settings → Git Proxy.
Usage
- Enter your proxy address (e.g.
127.0.0.1:10808) and click Save. - Click Enable proxy — it configures:
- git (https):
git config --global http.https://github.com.proxy http://<addr> - SSH (
git@github.com:): a plugin-ownedProxyCommandon theHost github.comblock of~/.ssh/config, using theconnecttool shipped with Git for Windows
- git (https):
- Use Test connectivity to verify the proxy port and the
github.com:443/github.com:22tunnels. - Click Disable proxy when downloads finish — both configurations are removed immediately.
Screenshots
Enabled — git and SSH proxy are on.
Disabled — clicking Disable proxy turns both off and restores direct connections.
Security
- Only
github.comgit operations are affected (https and SSH). npm/pnpm package downloads are untouched. - The proxy address is validated (host characters + port range) and stored per profile at
<profile>/git-proxy.json. ~/.ssh/configedits are conservative: only plugin-ownedProxyCommandlines (the quoted-connect format this plugin writes) are ever replaced or removed — a pre-existing userProxyCommandline is kept and the plugin line is inserted before it (ssh_config is first-match-wins). Everything else in the file survives byte-for-byte; configs containingMatchsections or multi-hostgithub.comlines are left untouched (the UI reports this).- Mutating routes accept only same-origin POSTs.
Known limitations
- SSH proxying requires the
connecttool (ships with Git for Windows). Without it the SSH part is reported unavailable; https still works. - Authenticated proxies (user/password) are not supported.
- IPv6 proxy addresses are not supported.
- If the proxy software is off while the proxy is enabled, git operations fail until you disable it (the test button warns beforehand).
- Any user
ProxyCommandline that happens to match the plugin's format (quoted path +-H+%h %p) is treated as plugin-owned. - Editing a CRLF ssh config normalizes line endings to LF.
Development
pnpm install
pnpm test # vitest suites
pnpm typecheck
pnpm build # tsc host + tsdown client bundle (lib/client.js)
The client bundle is a __ModuleLoader__ factory (id dsh-git-proxy) served by client-modules via the exports["./client"] subpath.
License
MIT
Links
More in this category
Tencent/WeKnora#dsh-weknora★ 21028
Four read-only tools over a WeKnora knowledge base: list knowledge bases, hybrid passage search, reassemble one document's chunks in order, and WeKnora's own cited RAG or ReAct-agent answer with a resumable session id.
superdesigndev/treg★ 709
Tool catalog for agents: search ~2,600 external endpoints (SEO and SERP, backlinks, social, people and company enrichment, ad libraries, scraping) by the task you want done, read each one's parameters and per-call price, then call it with the credential injected server-side. Ships the skill plus an MCP row that stays disabled until TREG_TOKEN is set.
anysearch-team/anysearch-dsh★ 377
AnySearch-powered real-time web and vertical search provider for DeepSeek Harness.
EthanYoQ/Invoice-Downloader#dsh-invoice-downloader★ 285
Local IMAP invoice download, OCR, archive, and Excel reimbursement summaries for DeepSeek Harness.
omdsh-dev/dsh-data-agent★ 183
Let the AI connect to databases and write SQL for you.
zhaoolee/notes#dsh-plugin★ 155
Export DSH conversations as Smartisan Notes-style PNGs, or create and update Markdown notes in a configured account-scoped workspace.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.