Source association
Confirms the relationship among package, source repository, and publisher. It proves provenance only, not function or safety.
Registry methods and boundaries
Understand what each passing result proves, what it does not prove, and where public facts come from.
Registry presents source, runtime tests, permissions, risks, maintenance, and freshness separately instead of combining them into a vague trust or safety score.
Test evidence
Passing one stage does not automatically pass the next.
Confirms the relationship among package, source repository, and publisher. It proves provenance only, not function or safety.
Installs an exact version in isolation and boots DSH. This alone does not prove the plugin’s core capability works.
Runs an observable assertion for the plugin’s primary capability and records environment, input, result, and time.
Validates upgrade, uninstall, recovery, and cleanup separately. Any missing stage remains explicitly not tested.
Checks permissions, order, conflicts, outcome, and recovery when exact versions of multiple plugins run together.
Prioritize current Stable, NEXT, and Developer channels and record the exact DSH version or commit, profile, platform, architecture, and test time.
Permission declarations and Registry observations remain separate. Risks describe only evidenced exposure and never claim absolute safety.