lpeixin/dsh-qualityforge ↗★ 3

dsh-qualityforge

DeepSeek Harness bundle: systematic, audit-ready QA orchestration for finished projects — exhaustive test-method catalog, evidence-backed execution, and a per-item checkable report with P0–P3 severity for negotiating fix scope with the Harness. 适合需要对已完成项目进行系统化QA测试与工程缺陷扫描的开发者。

パッケージ
dsh-qualityforge
互換性
未検証
バージョン
0.1.0
ライセンス
MIT
最終更新
2026/10/01

インストール

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:lpeixin/dsh-qualityforge

ドキュメント

README 全文を読む ↗

Usage

1. Recon — qf_scan

{ "projectPath": "/path/to/project", "force": true }

Produces a project profile: stack and package manager, project type, languages, runnable commands (each with its source, e.g. package.json#scripts.test), test frameworks, CI/container/IaC/security tooling, documentation completeness, and confirmed engineering gaps (a missing lockfile, suspected hardcoded credentials, and so on). Secret findings record location and kind only — never the value.

2. Plan — qf_plan

{ "depth": "standard", "categories": ["sec-input", "api-semantics"], "includeAll": false }
depthitemsuse
smoke331pre-release blocker list
standard984normal delivery audit (default)
deep1295deep audit of an important release
exhaustive1363first full audit, compliance evidence

Every item gets a stable id (QF-001), a priority (P0–P3), a severity, a judgement mode (auto / agent analysis / human confirmation) and an explicit pass criterion. Re-running is safe: existing items keep their status and history; only reset=true rebuilds from scratch.

3. Run and probe — qf_exec / qf_probe

{ "presets": ["build", "typecheck", "lint", "test", "coverage", "audit", "secrets"] }
{ "urls": ["http://127.0.0.1:3000/health"], "expectStatus": 200, "itemId": "QF-512" }

qf_exec spawns only the preset commands discovered by recon (no shell, no arbitrary command strings); install is opt-in because it mutates the working tree. qf_probe is restricted to loopback http(s), GET/HEAD, with a truncated body.

4. Record conclusions — qf_record

{
  "items": [
    {
      "id": "QF-142",
      "status": "fail",
      "actual": "`ORDER BY ${sort}` is interpolated into SQL at src/api/orders.ts:88",
      "recommendation": "Map sort fields through an allowlist; return 400 otherwise",
      "files": ["src/api/orders.ts:88"],
      "repro": ["GET /api/orders?sort=id;DROP TABLE users--"],
      "evidence": ["SQL log shows the interpolated statement"],
      "cwe": ["CWE-89"],
      "effort": "S"
    }
  ]
}

Judgement discipline: fail (with reproduction) / pass (with evidence) / blocked (environment or dependency missing — do not record as fail) / na (does not apply, with a reason) / wontfix (risk accepted).

5. Report — qf_report

{ "reportPath": ".qualityforge/QUALITYFORGE-REPORT.md", "waveScope": "defects" }

Sections: how to use the report · verdict summary · priority & severity distribution · fix waves · problem list with one checkbox per defect · full checklist · skipped items · command evidence · project profile · re-test and sign-off table.

6. Negotiate fix scope — qf_update / qf_fixplan

Developers tick - [x] in the report (or `WONTFIX` / `DEFER` / `NA`); the Harness runs qf_update sync=true to read the ticks back. Ticking a defect sets it to fixed, pending re-test — only a re-test makes it verified.

Then pick a scope:

scopemeaning
alleverything still open
p0 / p0-p1blockers only / the minimum shippable fix set
defects (default)every failing or blocked item
pendingonly items not judged yet
ids + excludeIdsexplicit include/exclude

Output is a fix handoff sheet — per item: expectation, observation, location, suggestion — plus the constraints (touch only what is in scope, every fix must be verifiable, write ticks back when done).