1504 hand-written ranges pointing at workspace members become workspace:^, so pnpm pack substitutes each member's real version at publication: sibling peerDependencies follow the family version instead of being pinned at ^0.0.1, and a reference to a vendored package follows that package's own line. Without this, publishing 0.0.2 ships peer ranges naming a version that does not exist, and 0.0.1-rc.1 does not satisfy ^0.0.1 either. It also retires ranges that had gone stale against the workspace: ^4.0.0-rc.6 for a 4.0.0-rc.7 checkout, ^3.17.0 for schemastery 3.18.0. workspace:* stays where an exact published version is the point, which is how the Landlock entry pins its platform packages. A workspace constraint now requires the protocol, so a new package cannot reintroduce a hand-written range. The same constraint caught packages/boot/cmdline arriving on master without the publishable trio, which this change completes.
dsh-native-command
English | 中文
A zero-dependency no-shell execFile runner shared by host-native OS integrations: one runNativeCommand(command, args, signal) call spawns the executable directly (never a shell string), captures utf8 stdout/stderr, propagates the caller's abort into child termination, and hides the transient console window on Windows. Failures reject with the exit code and both captured streams attached, so callers classify (missing tool, cancelled, real failure) without re-running anything.
Its two consumers are the host-side native integrations: the directory-picker-native backend's OS chooser commands and the gateway's open-with-default-application hand-off (dsh-host-apiproxy host.openPath). The NativeCommandRunner type is their injectable command boundary.
It is a library, not a service or plugin: no ctx, registers nothing, holds no state, emits no events.
Surface
import { runNativeCommand, type NativeCommandRunner } from '@deepseek-ai/dsh-native-command'
Model Experience
None, as this is host-side subprocess plumbing; nothing here reaches a model request.
KV Cache effect
None; this package neither assembles nor sends a provider request.
Known Limitations and Deferred Work
- No output bounding — both streams buffer unbounded in memory; every current caller invokes small native tools whose output is a path or an error line. Adopt
dsh-retentionbounding before pointing this at commands with meaningful output volume.