Registry methods and boundaries

Validation standards

Understand what each passing result proves, what it does not prove, and where public facts come from.

This is not a “safety certification”

Registry presents source, runtime tests, permissions, risks, maintenance, and freshness separately instead of combining them into a vague trust or safety score.

Browse with these standards

Test evidence

Five independent validation dimensions

Passing one stage does not automatically pass the next.

1

Source association

Confirms the relationship among package, source repository, and publisher. It proves provenance only, not function or safety.

2

Install and boot

Installs an exact version in isolation and boots DSH. This alone does not prove the plugin’s core capability works.

3

Functional smoke

Runs an observable assertion for the plugin’s primary capability and records environment, input, result, and time.

4

Full lifecycle

Validates upgrade, uninstall, recovery, and cleanup separately. Any missing stage remains explicitly not tested.

5

Composition validation

Checks permissions, order, conflicts, outcome, and recovery when exact versions of multiple plugins run together.

DSH version compatibility

Prioritize current Stable, NEXT, and Developer channels and record the exact DSH version or commit, profile, platform, architecture, and test time.

  • Declared support:Provided by the plugin author.
  • Observed pass:Produced by a Registry TestRun.
  • Not tested:Means current evidence is absent; it is neither a failure nor a pass.

Permissions and risks

Permission declarations and Registry observations remain separate. Risks describe only evidenced exposure and never claim absolute safety.

  • Missing information is shown as unknown.
  • Every evidence item binds to an exact plugin version.
  • Stale evidence remains in history but does not count as current coverage.

Four information authorities

Publisher contentUntrusted text for reading onlyRegistry observationsAutomated collection or manual reviewTest evidenceTestRun in an exact environmentControl metadataVersion, freshness, and withdrawal state