mirror of
https://github.com/deepseek-ai/deepseek-harness
synced 2026-08-15 21:04:50 +00:00
Every package under packages/, apps/, and vendor/ drops "private": true and declares publishConfig.access "restricted": the repository now states which packages it publishes instead of deciding it at publish time. Each one also declares its repository and directory, which is how a consumer of a private package reaches its source. The Landlock packages move to restricted with them. They have never been published, so nothing anonymous depends on them today, and the whole @deepseek-ai scope stays private. The workspace constraint that required every package to be private now applies to non-members only, and asserts the publishable trio on each release member.
workflow/ — dynamic-workflow capability family
English | 中文
This family runs model-authored orchestration workflows over subagents and exposes general and fixed-policy tools to the model.
| Package | Role | ctx key |
|---|---|---|
workflow/ |
Defines workflow execution and lifecycle events | ctx.workflows |
workflow-workerthread/ |
Runs workflow scripts in worker threads | registers on ctx.workflows |
tool-workflow/ |
Exposes general workflow execution to the model | registers on ctx.tools |
tool-ralph/ |
Exposes the fixed fresh-agent Ralph workflow | registers on ctx.tools |
Worker threads isolate workflow execution from the host event loop but are not a security boundary. See the dynamic-workflow and Ralph tool decisions.
The subsystem reference — start requests, WorkflowMeta, results, live runs, workflow/* events — is docs/subsystems/workflow.md; decisions in the dynamic-workflows and Ralph consumer Agent Notes.