The DeepSeek Harness changelog

DeepSeek Harness ships fast and breaks things — that is what a developer preview is for. This page tracks every official dsh release: what was added, what broke, and what it means if you write or install plugins. The official release notes are the authoritative source; what we add is a summary you can read in a minute, and the plugin-ecosystem context the notes leave out.

Current version

v0.1.2-alpha.42026-09-01

The latest DeepSeek Harness release is v0.1.2-alpha.4, published on 2026-09-01. The quick start — npx @deepseek-ai/dsh web — fetches the newest build every time you run it, so there is nothing to update. Building from source? Pull and rebuild, but read the storage note under rc.8 first.

v0.1.2-alpha.42026-09-01

Official release notes

A day after the session backend was removed, the session API is rewritten — the third release in a row to move ground under plugins that touch sessions.

Highlights

  • Parent agents and continuable child agents now exchange follow-up messages through send_message, replacing the one-way report tool.
  • Custom model discovery reuses Profile request headers, and the model catalog gains search and filtering.
  • web_fetch is on by default for the Python SDK, Headless, ACP and custom Profiles; Web PTC Mode stops handing the model a general-purpose workflow tool.
  • Very long conversations render with less overhead during response streaming, interface layout, and navigation previews.

Breaking change

`Session.events` is gone, replaced by on-demand reads — seq, eventAt() and snapshotEvents(). SessionSeq and SessionLogOffset are now distinct strong types, and the notes explicitly tell developers to check compatibility. The one-way report tool also gives way to send_message.

For plugin authors

This is the third consecutive release to move the session layer: rc.8 changed the SQLite format incompatibly, alpha.3 removed the optional SQLite session backend, and alpha.4 rewrites how session events are read. If your plugin reads sessions or reports into them, expect to touch it on almost every release for now — pin a version you have tested rather than tracking the line.

v0.1.2-alpha.32026-08-31

Official release notes

A day after alpha.2, mostly polish for long conversations — plus one removal that needs action before you upgrade.

Highlights

  • Long conversations get right-hand navigation that previews and jumps to every paginated turn, including ones not yet loaded.
  • Rendering long conversations uses less memory, and syntax highlighting keeps up better.
  • Images added or queued while a turn is running now echo correctly and deliver reliably; continuable subagents accept images in follow-up messages too.
  • Fixes: read_image reads attachments with no file extension, Tab completes the highlighted slash command while the menu is open, and backend stalls are no longer mistaken for a dropped connection.

Breaking change

The optional SQLite Session persistence backend is removed. Existing content is not deleted, but you need an older build to export it — so export before you upgrade, not after.

For plugin authors

Nothing in this build touches the loader or the plugin API. It is, however, the second time this line has changed session storage underneath you: rc.8 changed the format incompatibly, and now the optional backend is gone altogether. If your plugin reads session data directly rather than going through the harness, treat that path as unstable.

v0.1.2-alpha.22026-08-30

Official release notes

A three-day follow-up to alpha.1 that walks one of its removals back.

Highlights

  • Plugins are listed by scope now — conversation versus global — with Agent Preset switching and search across presets.
  • The interface surfaces connection failures, retries on its own, and offers an immediate reconnect; active schedules appear in the conversation header.
  • Every answer ends with its token usage and elapsed time, expandable to full statistics, and a failed web_search names the endpoint it actually hit.
  • Fixes: startup failures and dead HMR on Node.js 24.0–24.11.1, and breadcrumbs vanishing when you drill into directories from the @ menu with a mouse.

For plugin authors

SessionEvent.ignorable, removed in alpha.1, is restored — that removal was walked back, so hold off on rewriting anything that depended on it. The @Remote gateway alpha.1 migrated you to now wraps call failures in a single RemoteError type. Nothing breaks in this build.

v0.1.2-alpha.12026-08-27

Official release notes

The largest release since launch, and the first to step back from rc to alpha. Under the interface work, two plugin-facing surfaces move: the legacy ApiProxy is gone, and the conversation view is split into modules.

Highlights

  • Plugins get two new places to live in the UI: provider sign-in controls on the Models settings page, and third-party interface languages you can register yourself.
  • Subagents gain real model control — inside the authorization you configure, an agent picks provider, model and reasoning effort, and whoever starts one can also set a maximum output length. Claude Code and Codex subagents take a configured model too.
  • ACP catches up with standard session control, model settings, MCP, permissions and cancellation, and the Python SDK runtime picks up a Windows x64 build.
  • Public WebFetch is on by default, with SSRF protection and no per-request approval; reaching the web UI across a network now requires the one-time token in the launch URL.
  • Conversations get lighter: startup and session loading transfer less, records take less disk, images appear the moment you send them, and each finished answer expands to its exact token usage.

Breaking change

The legacy ApiProxy interface was migrated and removed — everything goes through the @Remote gateway now. The conversation view was also split into focused modules, so code that imported it wholesale has to import the layer that owns each capability instead. Both land in an alpha, one step off the rc line.

For plugin authors

Past those two removals, official DeepSeek requests now carry the package name and version of every enabled plugin by default — deployments can turn that off — and can opt into incremental session-log uploads. The Safety Notice is blunter than it was: dsh has not been security-audited, and sandboxing, approvals and permissions do not guarantee isolation. That is the assumption our own reading of plugin risk already runs on.

v0.1.1-rc.22026-08-21

Official release notes

Five hours after rc.1, a quiet follow-up: the image path that release opened gets proper plumbing.

Highlights

  • The DeepSeek adapter now prefers the Files API for image uploads and reuses files it has already uploaded, instead of resending the bytes.
  • Images are resized and converted to whatever format the target model expects before the request goes out.

For plugin authors

Read alongside rc.8, which patched request failures from oversized and accumulated images, this is that same path getting built rather than patched: uploads are now deduplicated and sized before they leave. The release notes list no loader or plugin-API changes.

v0.1.1-rc.12026-08-21

Official release notes

A small release carrying one big fix: a sandbox escape is closed, and the multimodal groundwork finally gets a model that can see. The line moves from 0.1.0 to 0.1.1.

Highlights

  • The DeepSeek adapter gains DeepSeek-V4-Flash-Vision-Exp, an experimental multimodal visual-understanding model. rc.8 taught the harness to carry images around; this gives it something that reads them.
  • Security: confined processes could escape Bubblewrap sandbox restrictions through /proc/<pid>/root. Fixed. If you lean on the sandbox to contain plugin code, this is the build to be on — how we think about plugin risk.
  • Polish: responsive Markdown tables in conversations, honest precision when the cache-hit ratio sits at 99.x%, subagent conversation header navigation, and multiline ask_user_question answers with Shift+Enter.

For plugin authors

The sandbox fix is the one to act on: before this build, plugin code running under Bubblewrap confinement could reach outside it. The release notes list no loader or plugin-API changes, so what loaded on rc.8 should still load — but this is a preview line, so verify rather than assume. Our directory tracks the sandbox and runtime plugins that sit in this blast radius.

v0.1.0-rc.82026-08-19

Official release notes

The multimodal release. Six days after launch: images become first-class input, and two rival coding agents become installable components.

Highlights

  • Native image requests can be enabled on the DeepSeek model adapters; /goal and /plan take mixed image-and-text input; the @ menu can reference files and whole sessions.
  • Claude Code and Codex install on demand as subagent Profile Bundles, with non-interactive permission modes and multiple named instances for Codex — what that does to the rivalry.
  • Windows PTY terminals keep persistent PowerShell sessions, on by default in the Minimal preset.
  • Quality of life: faster forking of long sessions, concurrent web_search queries, a smaller dependency download, and dsh web now opens the browser for you.
  • The Python SDK runtime covers all four built-in agent presets and bundles what rg/glob search and MCP stdio tools need.

Breaking change

The SQLite backend was reworked — reads, writes and forks got faster and files smaller, but the storage format is incompatible and the notes name no migration path. Treat local session data as disposable when crossing this version.

For plugin authors

rc.8 also publishes brand guidelines: “DeepSeek Harness” is a registered trademark, projects are asked to use the DSH abbreviation in names instead of the full mark, and descriptive wording like “built on DeepSeek Harness” stays fine. If you maintain a plugin, check your repo's name against them.

v0.1.0-rc.72026-08-17

Official release notes

Four days in: the first stabilising release — plugin UI seams, subagent job management, and a renamed preset.

Highlights

  • Plugins can register their own settings cards in the harness UI.
  • Codex and Claude Code subagent tasks are managed through the Job Panel.
  • MCP and ACP gain durable image attachments, and PTC Mode forwards nested images.
  • The English built-in preset Code mode is renamed PTC mode; DeepSeek models gain a low reasoning-effort option (the default stays high).
  • Fixes: persistent-Bash latency in the Minimal preset, stack overflows when paginating long histories, sessions dying after max-token truncation, Safari cursor drift in the composer, and a node-pty 1.2 beta upgrade for broader terminal compatibility.

DeepSeek Harness went public as an MIT-licensed developer preview and collected roughly 95,000 GitHub stars in its first two days; at our last dataset refresh the repository stood at 207,390. The pitch is one idea taken seriously: models, tools, skills, sessions, sandboxes, filesystems, the loop and the UI are all plugins on the Cordis runtime, composed through a cordis.yml loader file.

Highlights

  • One-command quick start — npx @deepseek-ai/dsh web — serving a local web UI on 127.0.0.1:3080.
  • Four built-in presets: Standard, Code (renamed PTC in rc.7), Minimal for benchmarking, and Creator for assembling your own.
  • The README warns, in capital letters, that compatibility-breaking changes are coming — a warning rc.8 went on to make good.

Frequently asked questions

What is the latest version of DeepSeek Harness?
v0.1.2-alpha.4, released on 2026-09-01. It is a prerelease inside the v0.1 developer preview — there is no stable branch yet, and the line alternates between release candidates and alphas. Anything newer than this page's last review date will be on the official GitHub releases page.
What is PTC mode?
The built-in preset that used to be called Code mode; rc.7 renamed the English label. It is the mode in which the model orchestrates a task by generating and running code against the harness rather than calling each tool one by one. Same preset, new name — older write-ups that say Code mode are describing PTC mode.
Is DeepSeek Harness stable enough for production?
No, and it does not claim to be. It is a developer preview whose README warns about compatibility-breaking changes in capital letters, and the first week delivered two release candidates and an incompatible storage-format change. Build against it and experiment — just do not put it anywhere a broken upgrade costs you money.
How do I update dsh, and will my sessions survive?
Run via npx and every launch fetches the latest build; from source, pull and rebuild. Sessions are the caveat: rc.8 changed the SQLite storage format incompatibly and the release notes describe no migration, so assume local session data does not cross that upgrade.
Do updates break installed plugins?
They can. The loader format and plugin APIs are still being shaped, so a plugin that loads on one release candidate may fail on the next. Before relying on one, check when its repository last pushed — an actively maintained plugin tracks upstream churn; an abandoned one quietly stops loading. Every plugin page in our directory shows that freshness.

DSHarness is an independent directory of DeepSeek Harness plugins, not affiliated with DeepSeek AI. Summaries are condensed from the official release notes, which remain authoritative. Last reviewed 2026-09-02.