Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

manifestSha256

setting never mined JSON

A Claude Code settings key, read out of the shipped bundle. No mined inventory carries it: everything below comes from what this site has written about it.

Admin-allowed plugin marketplaces must be pinned to a fixed version to use an installation preference other than "available"

Not Anthropic's. This is the line from the earliest changelog entry here that named it, v2.1.281.

First seen — never in a mined build
Last seen — never in a mined build
Builds0 / 138on this box, as of v2.1.295
Written about v2.1.281 first named in a changelog, 23 Sep 2026

In the changelogs

4

Releases whose published page names manifestSha256.

  1. v2.1.281
    Admin marketplace allowlist: installationPreference is clamped without a pin

    Admin-allowed plugin marketplaces must be pinned to a fixed version to use an installation preference other than "available"

    found in this entry's text

  2. v2.1.281
    Cowork admin docs: missing manifestSha256 downgrades to 'available'; unreadable allowlist counts as empty

    Cowork admin docs: a URL marketplace entry with no manifestSha256 is treated as available, and an unreadable allowlist counts as empty

    named in this entry, found in this entry's text

  3. v2.1.281
    Managed marketplace auto_install/required entries without a pin are treated as available

    Managed auto_install or required marketplace entries without a pin are treated as available and flagged as a config warning

    found in this entry's text

  4. v2.1.281
    Plugin marketplace schema drops SHA/manifest hash requirements for auto_install/required

    Marketplace plugins set to auto_install or required no longer need a full commit SHA or a manifestSha256 hash

    found in this entry's text

First cited

2

The earliest release whose published evidence quoted manifestSha256 was v2.1.281, 23 Sep 2026. That is the oldest release this project wrote about it, so it is a floor on the name's age and not the release that introduced it. It is not a presence reading: which builds carried the name is the table below.

ReleaseDateThe span that was quoted
v2.1.28123 Sep 2026An `auto_install` or `required` entry without that pin (a full 40-character commit SHA in `ref`, or `manifestSha256` for a `url` source) is treated as `available` and reported as a config warning
v2.1.28123 Sep 2026with no \`manifestSha256\` at all the entry is treated as \`available\` (and a config warning says so)

Presence across releases

0

The miner has never read a build containing this name. It is here because a changelog entry of ours names it, which is evidence that it existed and not evidence of which releases carried it. The inventory starts at v2.1.138 and everything older than that was never mined.

Read out of the published npm bundle release by release, and out of Anthropic's own documentation as this site captured it. Nothing on this page is a description anybody here wrote about what the settings key does. All settings keys.

Feedback