Skip to main content
Glama
dongsheng123132

dsh-schema-migration-proof

DSH Schema Migration Proof

Offline, content-addressed evidence for recorded DeepSeek Harness schema migrations. It verifies fixed fixture envelopes for output determinism, idempotent reruns, reversible rollback, required invariants and explicit lossy-field disclosure without executing a migration or returning data bodies.

This is not a migration runner, database tool, recovery system, or second surface-contract verifier. dsh-recovery-proof tests isolated restore drills; dsh-surface-contract-proof compares ToolRuntime/MCP/CLI envelopes; dsh-lineage records object/action relationships. This project scores the evidence produced by a migration test harness whose tool revision and source/target schemas are pinned.

The manifest contains only stable IDs and SHA-256 digests. Body-, data-, payload-, secret-, credential-, prompt- and message-shaped fields are rejected. A required invariant that is missing, failed or unobserved fails closed. A reversible migration must prove rollback, and a lossy fixture must enumerate every disclosed loss field.

Surfaces

  • DSH: dsh_schema_migration_inspect, dsh_schema_migration_verify.

  • CLI: dsh-schema-migration-proof verify --workspace-root examples --migration migration.json --artifact-dir artifacts.

  • MCP: schema_migration_inspect_inline, schema_migration_verify_inline; bounded inline JSON only, no filesystem, network, child process or migration execution.

dsh plugin --profile web add github:dongsheng123132/dsh-schema-migration-proof
npm test
npm run check
npm run smoke:plugin
npm run smoke:mcp

MIT

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables offline, deterministic verification that one immutable artifact followed a declared build-to-production promotion chain, using only hash-based evidence and failing closed on incomplete or nonconformant gate records.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Offers proof-only tools to inspect and verify remediation closure receipts, deterministically confirming asset coverage, fixed artifact deployment, rescanning, deadline compliance, and zero-residual closure without executing scans or touching live systems.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables local inspection of AI model deployment artifacts without executing model code, returning SHA-256, structure, defect analysis, and evidence-gap findings in Gemini CLI conversations.
    Apache 2.0
  • A
    license
    A
    quality
    B
    maintenance
    Lets an assistant read recorded production AI agent runs — steps, model and tool calls with arguments, and outcomes — along with the findings of comparison runs that checked a prompt or model change against those recordings, and verify a signed evidence bundle offline with no account or network. It is strictly read-only: no tool starts a replay or comparison, so nothing can spend money or act without a person deciding.
    5
    3,236 PyPI
    Apache 2.0