Registry V4 Trust

Trust Center

A package is never marked trusted because it is popular or merely declares a signature. Trusted requires verified publisher ownership and successful cryptographic signature verification.

2packages
0trusted
0partially verified
2community
0blocked

Trusted means cryptographic

Digest equality confirms bytes, not signer identity. Trusted requires successful cryptographic verification plus verified publisher ownership.

Immutable release identity

Every installable Registry V4 release is pinned to a 40-character source commit and is resolved before the local transaction starts.

Fail closed

Revoked releases and critical security advisories are blocked by Resolver V2. Yanked releases are not selected for new installs.

Local authority

Marketplace, REST and MCP can return plans only. The local DSH Runtime owns permissions, filesystem writes, activation and rollback.

Evidence-backed packages

Registry trust signals

Marketplace →
communityMCP

DSH Go Marketplace

mcp:coeasy/dsh-go-marketplace@0.1.4

Read-only DSH package and ecosystem discovery through the canonical API V2 MCP endpoint.

Publisher ownership
—
Cryptographic signature
—
SLSA provenance
—
SBOM evidence
—
communityPLUGIN

DSH Go Marketplace Desktop

plugin:coeasy/dsh-go-marketplace-plugin@0.1.4

Desktop Marketplace UI for Package Protocol V2. Remote services are discovery-only; all local mutations are delegated to the authenticated Runtime Supervisor through Local Host API V2.

Publisher ownership
—
Cryptographic signature
—
SLSA provenance
—
SBOM evidence
—