Marketplace block and allow lists now match repos written differently, and accept owner-wide wildcards.
What's wrong with this entry?
blockedMarketplaces and strictKnownMarketplaces now match more reliably across equivalent spellings of the same repository.
- repo paths are normalized: percent-decoding, dot segments, and a trailing
.git <owner>/*entries are supported, with an explicit error log when a wildcard is used somewhere it is not allowed- the
ssh.github.comhost is folded into the github alias whenfoldGitHubAliasesis set, and git URLs are cross-matched against github-form entries - path patterns must not escape the repo
wildcards are only supported in github-form entries, as "<owner>/*"
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.242
Blocked skills-directory plugins say which policy to change
Both mention blocked marketplace strict known