Contents

v0.4.7: DSH 0.1.2-rc.1 compatibility

View source on GitHub

v0.4.7 promotes the published DSH 0.1.2-rc.1 release to dsh-mnemon's stable registry and development baseline. It retains complete source verification against the immediately preceding DSH 0.1.2-alpha.5 tag and a real WebUI backward regression on DSH 0.1.1-rc.2. PR #161, PR #162.

Compatibility changes

  • All 22 directly consumed DSH development packages are pinned to exact 0.1.2-rc.1 releases. Direct Store and Invariants dependencies close the published type and peer graph instead of relying on transitive installation accidents.
  • The child-token selector now imports SnapshotSelectorHook from its public owner, @deepseek-ai/dsh-client-store; the UI Slots package remains the owner of StoredEntry. This is a type-boundary correction and does not change runtime token accounting.
  • The lockfile contains one coherent rc.1 prerelease cohort. pnpm 11 release-age exceptions enumerate only the exact rc.1 packages present in that lockfile, while later @deepseek-ai publications remain quarantined.
  • DSH 0.1.2-alpha.5 stays covered by the source-overlay job, including Store and Invariants. Capability-based Session reads continue to support both alpha.5/rc.1 snapshots and rc.2's events[] property without parsing package versions.

Cloud WebUI authentication

The active deployment guide now follows the DSH 0.1.2-rc.1 transport: every page, RPC, and stream uses the browser session established from the Host's launch-token URL and signed, authority-bound cookie. --trusted-host remains a Host/Origin fence, and HTTPS plus deployment access controls remain required for a public entry.

The previous DSH 0.1.1-rc.2 procedure remains documented as an explicit rollback path. Its method-specific authority tiers still require the startup-only Mnemon remoteAccess: trusted-host override for remote settings, backup, Provider-connection, and broad-mutation channels. DSH 0.1.2-rc.1 and alpha.5 ignore that retained compatibility setting.

Upgrade and compatibility

Install stable DSH 0.1.2-rc.1, install dsh-mnemon@0.4.7 in every owning profile, and restart those profiles:

sh
npm install -g @deepseek-ai/dsh@0.1.2-rc.1
dsh plugin --profile web add dsh-mnemon@0.4.7
dsh plugin --profile headless add dsh-mnemon@0.4.7

DSH profiles have independent plugin rosters, so run only the profile commands that apply to the installation. Memory data, storage paths, Pack formats, Provider credentials, runtime configuration defaults, production dependencies, public package exports, and session projection state are unchanged. No migration or cache deletion is required.

Verification

The implementation and release candidate passed complete pnpm run verify on Node 24.18.0 with pnpm 10.13.1: 654 tests passed and one Windows-only test was skipped on macOS. All 110 deterministic build files, isolated Headless activation, all ten Node-compatible public entries, the 117-file package-content check (383,848 packed bytes; 1,707,083 unpacked bytes), publint, and attw passed.

PR #162 passed Linux Node 22.19/24, Windows Node 24, source-linked DSH 0.1.2-alpha.5, and bilingual contribution-policy jobs. Its pnpm 11.7 registry install checked 936 dependency entries against the exact release-age exclusion set.

Isolated WebUI profiles completed status loading, Memory System navigation, a synthetic conversation, the read-only save dialog, and reload persistence on DSH 0.1.2-rc.1. A separate DSH 0.1.1-rc.2 profile completed the same conversation and reload regression. Browser warning/error logs and matching Host diagnostics were empty. The screenshots display plugin version 0.4.6 because they capture the executable compatibility commit before this version-only release preparation; no runtime source changed afterward. See the environment record and screenshots.

Rollback

Reinstall dsh-mnemon@0.4.6 in the same profiles and restart them. No data conversion is needed. v0.4.6 was not released against DSH 0.1.2-rc.1, so return DSH to its former 0.1.1-rc.2 baseline as well when a fully verified rollback is required; follow the rc.2-specific cloud procedure if that profile is remotely exposed.

Previous release: v0.4.6.