Every package under packages/, apps/, and vendor/ drops "private": true and declares publishConfig.access "restricted": the repository now states which packages it publishes instead of deciding it at publish time. Each one also declares its repository and directory, which is how a consumer of a private package reaches its source. The Landlock packages move to restricted with them. They have never been published, so nothing anonymous depends on them today, and the whole @deepseek-ai scope stays private. The workspace constraint that required every package to be private now applies to non-members only, and asserts the publishable trio on each release member.
code-runtime/ — code-execution capability family
English | 中文
The code-execution capability seam (see capability seams): a runtime Service Definition for executing one model-written program against host-provided async bindings, capturing what it printed and returned; replaceable providers; and the tool registry's Code Mode Consumer (tools: { mode: code } — the run_code tool and the SDK generated in the loaded runtime's language). Design is in the Code Mode Agent Note. Product packages.
| Package | Role | ctx key |
|---|---|---|
code-runtime/ |
Service Definition and shared vocabulary | ctx.codeRuntime |
code-runtime-worker/ |
Worker-thread backend | registers ctx.codeRuntime |
Providers register the service without changing its Consumer. The child READMEs own language, isolation, and execution-budget details.
The subsystem reference — run requests/results, binding namespaces, the failure taxonomy — is docs/subsystems/code-runtime.md.