1504 hand-written ranges pointing at workspace members become workspace:^, so pnpm pack substitutes each member's real version at publication: sibling peerDependencies follow the family version instead of being pinned at ^0.0.1, and a reference to a vendored package follows that package's own line. Without this, publishing 0.0.2 ships peer ranges naming a version that does not exist, and 0.0.1-rc.1 does not satisfy ^0.0.1 either. It also retires ranges that had gone stale against the workspace: ^4.0.0-rc.6 for a 4.0.0-rc.7 checkout, ^3.17.0 for schemastery 3.18.0. workspace:* stays where an exact published version is the point, which is how the Landlock entry pins its platform packages. A workspace constraint now requires the protocol, so a new package cannot reintroduce a hand-written range. The same constraint caught packages/boot/cmdline arriving on master without the publishable trio, which this change completes.
dsh-brand
English | 中文
The Branded<B> nominal-typing primitive — a tiny, type-only package (no runtime code, no harness-package dependency) shared by every package that owns a cross-boundary id.
What Branded is
A brand makes structurally-identical strings non-interchangeable at the type level: a SessionId cannot be passed where a CallId is expected, even though both are plain strings at runtime.
import type { Branded } from '@deepseek-ai/dsh-brand'
export type SessionId = Branded<'SessionId'>
/** Brand a string as a SessionId (a plain cast — zero runtime cost). */
export function SessionId(id: string): SessionId {
return id as SessionId
}
Construction goes through the per-id factory in the owning package. Comparison, logging, JSON serialization, and the wire format behave as for an ordinary string; the brand is erased at compile time.
Policy: brand ids that cross package boundaries
A package brands the ids it owns — CallId in dsh-llm, the shared agent/session SessionId in dsh-session, and TaskId in dsh-tasks. Brand cross-package ids that could plausibly be confused; not every string needs one.
This package owns only the primitive. Keeping it dependency-free lets dsh-tasks, for example, brand TaskId without importing an unrelated capability package merely to reach Branded.