rc.8 still has no privileged core, and the Web UI still has no login
dsh-v0.1.0-rc.8 (2026-08-19, SHA 141eb6fe) is still prerelease. The architecture page at that pin still says every part is a plugin and a patch can replace any row. The `never` approval policy is decided before waterfall dispatch, so a later prepend cannot bypass that one mode; replacing the approval row by patch still can. The request-trust module still says it is not an auth layer. trustedHosts is a Host grant, not a password. rc.8 adds Claude Code and Codex subagents as Profile Bundles with wrapper-owned non-interactive permission modes.
What this changes for operators
- Still a developer preview. Do not expose the port.
- Read architecture.md at 141eb6fe before installing a plugin. Inspect a bundle's permission mode; do not attribute it to Claude Code or Codex alone. Pin bundle packages at 0.1.0-rc.8; npm latest on those packages is still 0.0.1-rc.1.
Primary sources
- github_release 2026-08-20-deepseek-harness-still-prerelease-gate-still-a-plugin-ui-still-unauthenticated deepseek-ai/deepseek-harness / dsh-v0.1.0-rc.8
- official_docs 2026-08-20-deepseek-harness-still-prerelease-gate-still-a-plugin-ui-still-unauthenticated deepseek-ai/deepseek-harness / docs/architecture.md
- tagged_commit_file 2026-08-20-deepseek-harness-still-prerelease-gate-still-a-plugin-ui-still-unauthenticated deepseek-ai/deepseek-harness / packages/client/connection/src/api-request-trust.ts
Signal metadata
Source findings
- 2026-08-20-deepseek-harness-still-prerelease-gate-still-a-plugin-ui-still-unauthenticated 2026-08-20-deepseek-harness-still-prerelease-gate-still-a-plugin-ui-still-unauthenticated
Featured in
- The Classifier Is Off / 2026-08-20
Run: 2026-08-20-brief-2026-08-17_2026-08-20-frontier-v0
Schema: bitter.frontier_signals.v0 / ID: 2026-08-20-deepseek-rc-8-still-the-plugin-gate
Research evidence and publication history are open in the repository.