Files
deepseek-harness/vendor/hmr
imccyu a213befd0f build(release): publish the vendored framework and the native packages publicly
The three release sequences shipped with publishConfig.access: restricted, so
nothing in the @deepseek-ai scope was installable from outside the organization.

A restricted dependency is what actually blocks a public consumer: every harness
package declares the vendored framework as a peerDependency, and
dsh-sandbox-local declares the Landlock entry as a dependency. Those two
sequences therefore go public first — the nine vendor/* packages and the three
native/landlock-run packages — while the dsh family stays restricted until its
own sequence is opened deliberately. No public package requires a restricted one
in this arrangement.

Access is now per sequence, so no publish path can pass --access: one flag
cannot express two levels and would override the manifest that owns the fact.
publish.ts stops passing it, matching the native workflow, and
check-workspace-constraints holds each manifest to its own sequence's level,
which is what stops the scope from drifting one package at a time.

Harness consumers reference the Landlock entry as workspace:^ instead of
workspace:*, so a published harness package accepts the entry's patch and minor
releases. The entry keeps workspace:* for its platform packages, where the
binary must match the entry version exactly.

Two rationales that named a private registry no longer describe the vendored
sequence; they now state the durable reason, which is that the verification must
not depend on the registry already carrying matching versions.
2026-08-13 14:05:48 +08:00
..

@cordisjs/plugin-hmr

Hot module replacement for loader-managed Cordis plugins.

The HMR plugin watches source files, traces Node's module graph, clears affected module caches, and reloads only the plugin entries that depend on changed application files. Changes to framework-level dependencies fall back to loader.exit(), letting the host process restart.

Module watches canonicalize their existing base directory before opening Chokidar. Exact config watches likewise canonicalize the deepest existing ancestor, then restore any missing suffix. Callbacks and diagnostics retain the requested absolute filename, while the native backend receives one filesystem spelling even when Windows supplied an 8.3 alias.

Requirements

  • @cordisjs/plugin-loader
  • @cordisjs/plugin-timer
  • A runtime that exposes Node's internal module loader. The package throws if the loader service has no internal module loader available.

Usage

- id: timer
  name: '@cordisjs/plugin-timer'
- id: hmr
  name: '@cordisjs/plugin-hmr'
  config:
    root:
      - src
    ignored:
      - '**/node_modules'
      - '**/.*'
    debounce: 100

Config

Field Description
base Optional base directory resolved from ctx.baseUrl.
root Chokidar roots to watch. Defaults to ['.'].
ignored Picomatch patterns excluded from watch and reload analysis.
debounce Milliseconds to wait before processing a burst of changes.

Events

Event Description
hmr/change Emitted for changed files that are not handled by plugin reload or config reload.
hmr/reload Emitted after one or more plugin entries are reloaded.