dsh-schema-migration-proof
DSH Schema Migration Proof
Офлайн-доказательство с адресацией по содержимому для зафиксированных миграций схем DeepSeek Harness. Оно проверяет фиксированные оболочки фикстур на детерминизм вывода, идемпотентные повторные запуски, обратимый откат, требуемые инварианты и явное раскрытие полей с потерями без выполнения миграции или возврата тел данных.
Это не средство запуска миграций, не инструмент для работы с базой данных, не система восстановления и не ещё один верификатор контрактов поверхности. dsh-recovery-proof проверяет изолированные тренировочные восстановления; dsh-surface-contract-proof сравнивает оболочки ToolRuntime/MCP/CLI; dsh-lineage записывает связи объект/действие. Этот проект оценивает доказательства, полученные с помощью тестового стенда миграций, в котором зафиксированы ревизия инструмента и исходная/целевая схемы.
Манифест содержит только стабильные идентификаторы и SHA-256-дайджесты. Поля, имеющие форму тела, данных, полезной нагрузки, секрета, учётных данных, подсказки или сообщения, отклоняются. Требуемый инвариант, который отсутствует, нарушен или не наблюдался, приводит к отказу в закрытом режиме. Обратимая миграция должна доказывать откат, а фикстура с потерями должна перечислять каждое раскрытое поле потерь.
Поверхности
DSH:
dsh_schema_migration_inspect,dsh_schema_migration_verify.CLI:
dsh-schema-migration-proof verify --workspace-root examples --migration migration.json --artifact-dir artifacts.MCP:
schema_migration_inspect_inline,schema_migration_verify_inline; только ограниченный встроенный JSON, без файловой системы, сети, дочерних процессов или выполнения миграций.
dsh plugin --profile web add github:dongsheng123132/dsh-schema-migration-proof
npm test
npm run check
npm run smoke:plugin
npm run smoke:mcpMIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Read-only verifier for 25 ProofRelay MCP tools and non-confidential evidence bundles.
Verifies Bernstein run receipts and hash chains; lists the shipped presets and adapters. Read-only.
Reviewed public-data search and execution with provenance and verifiable integrity receipts.
Browser-local and CLI static evidence for deployed AI model artifacts.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables offline, deterministic verification that one immutable artifact followed a declared build-to-production promotion chain, using only hash-based evidence and failing closed on incomplete or nonconformant gate records.MIT
- AlicenseNot gradedqualityCmaintenanceOffers proof-only tools to inspect and verify remediation closure receipts, deterministically confirming asset coverage, fixed artifact deployment, rescanning, deadline compliance, and zero-residual closure without executing scans or touching live systems.MIT
- AlicenseNot gradedqualityBmaintenanceEnables local inspection of AI model deployment artifacts without executing model code, returning SHA-256, structure, defect analysis, and evidence-gap findings in Gemini CLI conversations.Apache 2.0
- AlicenseAqualityBmaintenanceLets an assistant read recorded production AI agent runs — steps, model and tool calls with arguments, and outcomes — along with the findings of comparison runs that checked a prompt or model change against those recordings, and verify a signed evidence bundle offline with no account or network. It is strictly read-only: no tool starts a replay or comparison, so nothing can spend money or act without a person deciding.53,236 PyPIApache 2.0