deja-vu avatar

deja-vu

Memory for Claude Code, Codex, Cursor and 35 more coding agents, built from the session history already on your disk. Local search, MCP and hooks, no LLM, one Go binary.

Ecosystem appDeveloperKnowledgeAI ModelsStorageMemoryFileWeb search
Verification
L5 · Ecosystem app
Risk
Low
Health
Active
Trust
Silver

Install verification: Ecosystem app: not installed via dsh plugin add, so the L1-L5 plugin install-verification ladder does not apply; the security scan still runs.Install verification details →

Install verification badge dsh 0.1.7-rc.2

What it doesAI

Memory for coding agents that indexes past sessions on disk and recalls them locally without embeddings.

  • Indexes sessions from multiple coding agents on disk
  • Recalls past context across any agent locally
  • No LLM or embeddings; single Go binary
developerAImemoryAIfileAI

Capability tags are AI-inferred or rule-extracted from the README (see badge) — vocabulary-limited, not install-verified. AI = inferred; README = literal keyword from the readme.

Installation

GitHub repository

Ecosystem apps are not installable via dsh plugin add: desktop / web shells install or deploy through their own release channel (GitHub Releases or the project site).

The level reads L5 · Ecosystem plugin / L5 · Ecosystem app per the three-way classification (the L1-L5 ladder does not rate them); the security scan still runs.

Verification & Compatibility

Grouped by plugin version: each card lists the dsh versions actually tested against that artifact version and their install verdicts (L5 wins). Untested combinations are omitted — absence means untested, never assumed compatible. L1–L3 are a plugin-level static archive (independent of the dsh version — the same verdict on every dsh row): they sit in each row's level grid next to L4/L5, marked "static", while their evidence is stored once per plugin inside that row's "checks & evidence" instead of being duplicated per version.

External credentials (plugin-level): none detected

Install compatibility matrix (rows = plugin versions〔latest 5〕, columns = dsh versions〔latest 5〕)
At-a-glance → evidence in the cards below
plugin \ dshdsh 0.2.0-rc.1dsh 0.1.7-rc.2dsh 0.1.7-rc.1dsh 0.1.7-alpha.2dsh 0.1.6-alpha.2
0.21.5·····
0.21.4·····
0.21.3·····
0.21.2·✓···
0.21.1·····
Install compatibility (by plugin version, dsh versions within)
Legend:✓ L5 runtime verified○ ecosystem plugin◼ ecosystem app✗ failed
0.21.5npm2026-10-04

@vshulcz/deja-vu

◼prehistory2026-10-04ecosystem app
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: unknown
  • • Plugin artifact: npm · @vshulcz/deja-vu@0.21.5
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Unknown
No install verdict — an ecosystem app, not installable via `dsh plugin add`; ships through its own release channel (shown as L5 · Ecosystem app; the L1-L5 ladder does not rate it)
ecosystem app

ID: deja-vu@0.21.5@dshunknown · profile: l4-sandbox

Issued: 2026-10-04 · expires: 2026-10-11

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-10-04
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-10-04
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-10-04
spec @vshulcz/deja-vu · channel npm package · outcome ran · exit 0
check took: 84.8s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-10-04
spec @vshulcz/deja-vu · channel npm package · outcome ran · exit 0
check took: 84.8s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-10-04
spec @vshulcz/deja-vu · channel npm package · outcome ran · exit 0
check took: 84.8s
Resolved version recorded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-10-04
spec @vshulcz/deja-vu · channel npm package · outcome ran · exit 0
check took: 84.8s
L5 · Run tested? Unknown

not present in web-profile loader inventory

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-10-04
spec @vshulcz/deja-vu · install mode reused L4 scratch
check took: 20ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-10-04
ready line dsh web: http://127.0.0.1:51478/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-10-04
path / · HTTP 200 · took 20ms
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-10-04
verdict not-found · entries 149
phases: active 121 · null 28
not present in web-profile loader inventory

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

0.21.4npm2026-10-03

@vshulcz/deja-vu

◼prehistory2026-10-03ecosystem app
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: unknown
  • • Plugin artifact: npm · @vshulcz/deja-vu@0.21.4
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Unknown
No install verdict — an ecosystem app, not installable via `dsh plugin add`; ships through its own release channel (shown as L5 · Ecosystem app; the L1-L5 ladder does not rate it)
ecosystem app

ID: deja-vu@0.21.4@dshunknown · profile: l4-sandbox

Issued: 2026-10-03 · expires: 2026-10-10

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-10-04
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-10-04
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-10-03
spec @vshulcz/deja-vu · channel npm package · outcome ran · exit 0
check took: 110.4s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-10-03
spec @vshulcz/deja-vu · channel npm package · outcome ran · exit 0
check took: 110.4s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-10-03
spec @vshulcz/deja-vu · channel npm package · outcome ran · exit 0
check took: 110.4s
Resolved version recorded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-10-03
spec @vshulcz/deja-vu · channel npm package · outcome ran · exit 0
check took: 110.4s
L5 · Run tested? Unknown

not present in web-profile loader inventory

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-10-03
spec @vshulcz/deja-vu · install mode reused L4 scratch
check took: 33ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-10-03
ready line dsh web: http://127.0.0.1:54619/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-10-03
path / · HTTP 200 · took 33ms
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-10-03
verdict not-found · entries 149
phases: active 121 · null 28
not present in web-profile loader inventory

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

0.21.3npm2026-09-29

@vshulcz/deja-vu

Ecosystem app: not installed via dsh plugin add (a desktop / web shell) — its level reads L5 · Ecosystem app.

0.21.2npm✓ 1 runtime-verified2026-09-25

@vshulcz/deja-vu

✓dsh 0.1.7-rc.22026-09-25L5 · runtime verified
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.7-rc.2
  • • Plugin artifact: npm · @vshulcz/deja-vu@0.21.2
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Passed
Install + runtime smoke verified in the dsh sandbox — installs and runs
L5 · runtime verified · valid for dsh 0.1.7-rc.2

ID: deja-vu@0.21.2@dsh0.1.7-rc.2 · profile: l5-web-smoke

Issued: 2026-09-25 · expires: 2026-12-24

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-10-04
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-10-04
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec @vshulcz/deja-vu · channel npm package · install mode reused L4 scratch
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec @vshulcz/deja-vu · channel npm package · install mode reused L4 scratch
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec @vshulcz/deja-vu · channel npm package · install mode reused L4 scratch
L5 · Run tested✓ Passed

active in loader tree (150 entries)

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec @vshulcz/deja-vu · install mode reused L4 scratch
check took: 18ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-25
ready line dsh web: http://127.0.0.1:54830/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-25
path / · HTTP 200 · took 18ms
Plugin active in inventory✓ Passed
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-25
verdict active · entries 150
match: include:deja · dsh-deja · phase active
phases: active 122 · null 28

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

0.21.1npm2026-09-23

@vshulcz/deja-vu

Ecosystem app: not installed via dsh plugin add (a desktop / web shell) — its level reads L5 · Ecosystem app.

Only the latest 3 published versions are shown; source-snapshot (commit hash) groups, unstated groups and older versions are omitted — the full archive stays in the data layer (snapshot/unstated groups appear only when a plugin has no published version).

Author badges

Embed the official badges in your README to showcase security & install-test status:

dsh.so risk
`[![dsh.so risk](https://www.dsh.so/badge/deja-vu.svg)](https://www.dsh.so/artifact/deja-vu/)`
dsh 0.1.7-rc.2 install verified
`[![dsh.so install · dsh 0.1.7-rc.2](https://www.dsh.so/badge/install/deja-vu@0.1.7-rc.2.svg)](https://www.dsh.so/artifact/deja-vu/)`

Security Report

Automated static scan, not manual review.

DSH.SO VETPASSED577098
Automated review · daily
PASSED

Vet static analysis found no suspicious behavior — verdict is clean.

0 critical·0 high·0 medium
plugin versionv0.21.7
scanned version0.21.7npm2026-10-06
current version0.21.7same version
vet verdictclean · npm

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

No critical or warning findings.

Activity

Last commit 2026-10-06 · activity: Active

• Repo created: 2026-07-14

• Stars: ★ 1,133 · Forks: 110

• Health: Active — committed within last 30 days

Source

GitHub: github.com/vshulcz/deja-vu

Was this page helpful?