The current alignmentnpm latest and next, the official GitHub release, and the public default branch all point to rc.7. Capture each coordinate anyway because tags and branches can move.

Separate four signals.

  1. Dist-tag: what a fresh unpinned install would resolve now.
  2. Published artifact: the immutable package version and integrity metadata downloaded from npm.
  3. Installed artifact: the package actually selected by the current global install, project, cache, or launcher.
  4. Source revision: the commit used for code links and mechanism claims. It may not reconstruct an unpublished package exactly.

Capture the executable evidence.

Run this before changing the installation:

npx @deepseek-ai/dsh --version
npm view @deepseek-ai/dsh dist-tags --json
npm view @deepseek-ai/dsh@0.1.0-rc.7 dist.integrity gitHead --json

Also record the exact launch command, Node version, operating system build, profile, and resolved configuration. If the first command downloads a package, preserve that output: it is part of the reproduction.

Pin experiments, not assumptions.

npx @deepseek-ai/dsh@0.1.0-rc.7 --version
npx @deepseek-ai/dsh@0.1.0-rc.7 web

An explicit version makes a clean-room retry comparable. It does not prove that an existing failing process used the same artifact, so capture first and reinstall second.

Write incident claims with both coordinates.

A useful report says: “Observed on npm package 0.1.0-rc.7; source mechanism inspected at commit 99f6f02.” If those coordinates differ, label the source conclusion source-consistent rather than reproduced.

Primary evidence.

Keep the evidence boundary visible

Check the live field status.

Known reports are labeled observed, source-consistent, or verified—never silently blended.

Open Field Status