Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`, `verify-translation-pairing --write` for the touched bilingual pairs, `gen-doc-graphs`, and one typert snapshot whose ids embed character offsets. `pnpm run rescope-vendor --check` verifies the result. Renames nine vendored packages (cordis, cosmokit, schemastery and the six @cordisjs plugins) and every reference that resolves them: manifest names and dependency keys, module specifiers including declare-module merges, cordis.yml plugin names, tsconfig paths, every Markdown fence, and `docs/` prose. Directory names, upstream versions, and dependency ranges are unchanged, so vendor/README.md still reads as an upstream snapshot; its manifest table gains an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed at each fork's origin. The tutorial tier follows the rename end to end: its yaml fences named plugins the Loader can no longer resolve, its `ts ignore-check` fences disagreed with the compiled fences beside them, and its prose quoted both. The contracts that told readers to keep upstream names — the root convention and the vendoring cookbook's tree comment and manifest invariant — now say to rescope instead. Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle purity gate now names the vendored libraries a browser bundle inlines, and the files where a bare `cordis` is an agent-preset id keep that product data.
dsh-native-command
English | 中文
A zero-dependency no-shell execFile runner shared by host-native OS integrations: one runNativeCommand(command, args, signal) call spawns the executable directly (never a shell string), captures utf8 stdout/stderr, propagates the caller's abort into child termination, and hides the transient console window on Windows. Failures reject with the exit code and both captured streams attached, so callers classify (missing tool, cancelled, real failure) without re-running anything.
Its two consumers are the host-side native integrations: the directory-picker-native backend's OS chooser commands and the gateway's open-with-default-application hand-off (dsh-host-apiproxy host.openPath). The NativeCommandRunner type is their injectable command boundary.
It is a library, not a service or plugin: no ctx, registers nothing, holds no state, emits no events.
Surface
import { runNativeCommand, type NativeCommandRunner } from '@deepseek-ai/dsh-native-command'
Model Experience
None, as this is host-side subprocess plumbing; nothing here reaches a model request.
KV Cache effect
None; this package neither assembles nor sends a provider request.
Known Limitations and Deferred Work
- No output bounding — both streams buffer unbounded in memory; every current caller invokes small native tools whose output is a path or an error line. Adopt
dsh-retentionbounding before pointing this at commands with meaningful output volume.