Trusted means cryptographic
Digest equality confirms bytes, not signer identity. Trusted requires successful cryptographic verification plus verified publisher ownership.
A package is never marked trusted because it is popular or merely declares a signature. Trusted requires verified publisher ownership and successful cryptographic signature verification.
Digest equality confirms bytes, not signer identity. Trusted requires successful cryptographic verification plus verified publisher ownership.
Every installable Registry V4 release is pinned to a 40-character source commit and is resolved before the local transaction starts.
Revoked releases and critical security advisories are blocked by Resolver V2. Yanked releases are not selected for new installs.
Marketplace, REST and MCP can return plans only. The local DSH Runtime owns permissions, filesystem writes, activation and rollback.
mcp:coeasy/dsh-go-marketplace@0.1.4Read-only DSH package and ecosystem discovery through the canonical API V2 MCP endpoint.
plugin:coeasy/dsh-go-marketplace-plugin@0.1.4Desktop Marketplace UI for Package Protocol V2. Remote services are discovery-only; all local mutations are delegated to the authenticated Runtime Supervisor through Local Host API V2.