Every package under packages/, apps/, and vendor/ drops "private": true and declares publishConfig.access "restricted": the repository now states which packages it publishes instead of deciding it at publish time. Each one also declares its repository and directory, which is how a consumer of a private package reaches its source. The Landlock packages move to restricted with them. They have never been published, so nothing anonymous depends on them today, and the whole @deepseek-ai scope stays private. The workspace constraint that required every package to be private now applies to non-members only, and asserts the publishable trio on each release member.
interaction/ — the human-collaboration plane
English | 中文
The services and plugins through which a human collaborates with a running agent — questions, approvals, permission presets, commands. These are product packages: real interfaces a person drives.
| Package | Role | ctx key |
|---|---|---|
commands/ |
Registers and dispatches human commands for interactive adapters. | ctx.commands |
user-approval/ |
Coordinates one-shot approval decisions. | ctx.approval |
permission/ |
Presents and persists user-facing permission presets. | ctx.permission |
user-interaction/ |
Defines the provider-neutral human question/answer seam. | ctx.userInteraction |
tool-ask-user/ |
Exposes human questions to the model. | (registers on ctx.tools) |
These packages integrate through existing agent and session contracts rather than changing the loop. Interactive applications provide the concrete command, approval, and question adapters; automation uses acp/, and runnable demo bundles live under examples/. The product dsh CLI composes these packages directly.
The subsystem references: approval.md, permission.md, user-interaction.md, and commands.md. The automation-only ACP transport is acp/, the SDK's JSON-RPC server half scaffold/server, and the shared bin boot glue boot/.