Plugin Install Ecosystem Report

The queue caught up — half the registry still isn't runtime-verified

Runtime verified (L5)Installed only (L4)FailedPlain dep (unmounted)
Vol.2 published 2026-09-10Verification batch 2026-09-08 17:18:15 (UTC+8)

Every dsh version with real install records, on one ladder — 0.1.2-α.1 → 0.1.2-rc.1 → 0.1.3-α.1 → 0.1.3-α.2. Runtime-verified by version: 5,543 → 6,252 → 6,448 → 7,175.

At a glance
Coverage is done14,494 of 14,496 listable plugins carry a real install verdict on 0.1.3-alpha.2; 2 untested.
Half of them still don't run7,175 pass L5 (49.5%), 3,202 fail, 4,085 are plain dependencies with no dsh.bundle.
Failure is one shape3,087 runtime failures — 2,853 of them (92.4%) record the same text on the same check.
14,496
Registry plugins
× 3 dsh versions
7,175
Runtime verified · L5
49.5% of registry
13,683
Installed · L4
94.4% of registry
4,085
Plain deps (unmounted)
no dsh.bundle
3,202
Failed
runtime 3,087 · install 115
7,287
Not runtime-verified
failed 3,202 + plain deps 4,085
14,494
0.1.3-alpha.2 tested
99.99% coverage
How to read this
  1. L5 wins — "runtime verified" requires a passing L5 (web boot · HTTP · loader inventory); L4 alone means installed, not running.
  2. Version-scoped — a verdict is valid only for the dsh version it was measured on; every figure below is scoped to 0.1.3-alpha.2.
  3. Gray is not broken — unknown = installed but declaring no dsh.bundle, so dsh mounts nothing: a plain dependency, not a failure.

A Verdict mix per versionstacked to max 14,494 · current 0.1.3-α.2

0.1.2-α.1
4,728
2,493
5,543
runs 5,543 · tested 12,764 · 08-28
0.1.2-rc.1
3,731
2,955
130
6,252
runs 6,252 · tested 13,068 · 09-03
0.1.3-α.1
3,746
3,009
121
6,448
runs 6,448 · tested 13,324 · 09-04
0.1.3-α.2
4,085
3,202
32
7,175
runs 7,175 · tested 14,494 · 09-07

B L4 installed vs L5 runsdecided pass rate · current 0.1.3-α.2

99%L4installed
69.9%L5runs
0.1.2-α.1
99.1%L4installed
68.7%L5runs
0.1.2-rc.1
99.2%L4installed
69%L5runs
0.1.3-α.1
99.2%L4installed
69.9%L5runs
0.1.3-α.2

C Registry mix · 0.1.3-alpha.214,496

7,175
run
Runtime verified (L5)7,175Failed3,202Plain dependency (no dsh.bundle)4,085Not tested2gray = no dsh.bundle → plain dependency, unmounted; not tested 2

D Install ladder L1 → L5 · 0.1.3-alpha.2bar = pass rate

L1 Foundrepo reachable · README14,458 · 97%
L2 Structuredmanifest valid & complete13,817 · 92.7%
L3 Install specparseable install command14,387 · 96.5%
L4 Install testedinstalls cleanly in sandbox13,683 · 93.1%
L5 Runtime verifiedweb boots · HTTP · inventory active7,175 · 48.6%

E Channel duel · 0.1.3-alpha.2delta 25.2%pp

npm · pinned tarball2,146 tested
71%19.7%8.9%
verified 1,524 · failed 423 · plain dep 191
source · tag / commit12,348 tested · 85.2% of verdicts
45.8%22.5%31.5%
verified 5,651 · failed 2,779 · plain dep 3,894
The gap is packaging, not breakage: failure rates are level, but 31.5% of source installs declare no dsh.bundle versus 8.9% of npm ones. other channel: 0.

F Runtime failure profile · 0.1.3-alpha.2records verbatim

115install failed · L43,087runtime failed · L5
plugin tree failed to load2,853
boot failed83
L5.4_PLUGIN_INVENTORY_ACTIVE67
duplicate loader entry id50
L5.3_HTTP_SERVED22
other recorded forms (2)12
buckets = the failing check's own recorded text; head form is 92.4% of runtime failures (234 across the other forms)
▾ core above the fold · reading / method / more below ▾

01 What the numbers say

An editorial read, not a second data source: every claim below points at a figure already shown above, and nothing new is introduced here.

The queue caught up — the loss is no longer "untested"

99.99% coverage: 14,494 of 14,496 listable plugins carry a real verdict on 0.1.3-alpha.2 (2 not tested). Of those, 7,175 run (49.5%), 3,202 fail (22.1%) and 4,085 are plain dependencies (28.2%). Runtime-verified rose 6,448 to 7,175 (+727, +11.3%) from the version Vol.1 closed on.

Scope. Coverage is a property of the queue, not the ecosystem: every L5 verdict landed inside one two-day batch (2026-09-08/09). Limitation. Untested is not failing — and here untested is 2. The open question is now verdict quality, not reach.

The channel gap is packaging discipline, not breakage

npm-pinned installs verify at 71% versus 45.8% for source installs (25.2%pp gap). Failure rates are nearly the same (19.7% npm vs 22.5% source) — the real split is the gray bucket: 31.5% of source installs declare no dsh.bundle versus 8.9% of npm ones.

Scope. Channel is the winning record's evidence.parsed.channel, with a same-version fallback; the "other" bucket is empty this window. Limitation. Declaring dsh.bundle is a packaging choice, not a quality score: an unmounted dependency is not a broken plugin.

Runtime failure is one shape, not a long tail

3,202 failures = 115 sandbox install failures (L4) + 3,087 web-runtime failures (L5). 2,853 of the runtime failures (92.4%) carry the identical record text "plugin tree failed to load" on check L5.2_WEB_BOOT_READY; the remaining 234 spread over 6 other recorded forms.

Scope. Buckets are the failing check's own summary text, verbatim; nothing is reclassified or renamed into a taxonomy. Limitation. One shared shape points at a common gate or cause, not at 3,087 independent plugin defects — this is a symptom tally, not a root-cause analysis.

The release train is ahead of the verification queue

Three dsh releases landed after the tested version — 0.1.5-alpha.1 (2026-09-08), 0.1.5-alpha.2 (2026-09-09) and 0.1.5-rc.1 (2026-09-10) — and carry zero verification records. Every figure in this report is scoped to 0.1.3-alpha.2.

Scope. Version scoping is deliberate: a verdict is only valid for the version it was measured on; older verdicts are kept as history and never silently upgraded. Limitation. The next version switch moves the current version, and these coverage and verified figures will drop until the retest queue catches up again. That is accounting, not regression.

02 Methodology

Q Is "installed" (L4) the same as "runtime verified"?

No. L4 means the sandbox install completed; L5 means the web runtime boots, serves HTTP and lists the plugin in the loader inventory. Only an L5 pass is counted as runtime-verified — 13,683 plugins install, 7,175 run.

Q Why does this report stop at 0.1.3-alpha.2 when newer releases exist?

Because 0.1.3-alpha.2 is the highest version with real records. 0.1.5-alpha.1 / 0.1.5-alpha.2 / 0.1.5-rc.1 are published but have not been run through the ladder yet; their columns would be empty. Coverage figures are version-scoped by construction, so they will drop at the next version switch and climb again as the queue catches up.

03 More

Q How should I read 3,202 failures?

As two different events. 115 never installed in the sandbox; 3,087 installed but failed the web runtime gate — 92.4% of them with the identical recorded text "plugin tree failed to load". Treat that as a shared gate symptom, not 3,087 independent plugin quality verdicts.

Q Is a runtime-verified plugin a safe plugin?

No — verification and security are independent axes. Runtime verification says the plugin installs and runs; it says nothing about what it does. Security is reported separately on each plugin page.

Cite this report

dsh.so — DeepSeek Harness Plugin Install Ecosystem Report, Vol.2 (published 2026-09-10).
Window: 0.1.2-alpha.1 -> 0.1.2-rc.1 -> 0.1.3-alpha.1 -> 0.1.3-alpha.2 · verification batch started 2026-09-08 17:18:15 (UTC+8)
Registry: 14,496 · runtime verified (L5) 7,175 · installed (L4) 13,683 · failed 3,202
https://dsh.so/reports/install-vol2/

Share

Post on X
Was this page helpful?