Follow Discord
Sweep 03 Oct 2026 · 20:28Z Build v2.1.289 510 read Stable v2.1.285 Latest v2.1.289 Next v2.1.289 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · claude-code

Marketplace reference changedplugins/marketplace-reference

Nearest release: v2.1.287, published 5 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Upstream edited this page at 1 Oct 2026 22:47 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 1 Oct 2026 23:07 UTC.

Upstream edited
Recorded here
Lines+11added
Lines−3removed
From line 135 where the diff opens
First seen 25 Sep 2026 this site's first read of the page
Recorded edits10to this page, all time

The whole hunk

from line 135, old and new numbered
/
lines
from line 135
135135| `github` | `repo`, `ref`, `sha` | GitHub repository in `owner/repo` form |
136136| `url` | `url`, `ref`, `sha` | Any git repository by URL |
137137| `git-subdir` | `url`, `path`, `ref`, `sha` | One subdirectory of a git repository, fetched with a sparse partial clone |
138| `npm` | `package`, `version`, `registry` | npm package, fetched with your npm client and unpacked without running install scripts |
138| `npm` | `package`, `version`, `registry` | npm registry package or tarball link, fetched with your npm client and unpacked without running install scripts |
139139| `archive` | `url`, `sha256` | Zip archive over HTTPS. Requires Claude Code v2.1.224 or later |
140140| `command` | `command`, `timeout`, `mode` | Directory printed by a command Claude Code runs on the user's machine. Requires Claude Code v2.1.229 or later |
141141 
from line 226
226226 
227227An `npm` source takes these fields:
228228 
229* `package`: a package name, or a scoped name such as `@your-org/formatter`
230* `version`: a version or range
229* `package`: a registry package name such as `@your-org/formatter`, a name with a version appended such as `@your-org/[email protected]`, or an `https` link to the package's tarball file
230* `version`: a version, a semver range, or a dist-tag, used when `package` is a package name with no version appended. Omit it to fetch `latest`
231231* `registry`: a registry URL for a package that isn't on the default registry
232232 
233233Claude Code fetches the package with your npm client. The package's install scripts, such as `preinstall` or `postinstall`, never run, and its dependencies aren't installed during the fetch. If the package has a supported lockfile beside its `package.json`, Claude Code installs those [Node.js package dependencies](/docs/en/plugins/loading#node-js-package-dependencies) in a separate step, also with scripts disabled.
234 
235Claude Code checks the `package` value before fetching anything. A refused value fails the install with a message that names the value and the reason. The refused values include:
236 
237* **A git address, a folder or `file:` path, or an `npm:` alias**: use a [`github`, `url`, or `git-subdir` source](#plugin-sources) for a git repository, a relative path for a folder in the marketplace, and the package's own name for an alias
238* **A tarball link on github.com, gist.github.com, gitlab.com, bitbucket.org, or git.sr.ht**: refused even when the link is a GitHub release download, unless it's a GitLab npm registry link under `gitlab.com/api/v4/`
239* **A tarball link over `http`**: refused unless it points at the installing user's own default npm registry
240 
241The `registry` URL must use `https` unless it is the installing user's own default npm registry. With any other `http` registry, the install fails before npm contacts it.
234242 
235243```json theme={null}
236244{
Feedback