Marketplace validation now warns about unsafe headersHelper and missing sha256 setups.
What's wrong with this entry?
Catalog validation gained errors and warnings for fetch credentials: an entry using headersHelper must inline its full manifest or the helper will not be run, headers/headersHelper on non-archive sources warn as ineffective, and an archive fetched with a helper but no sha256 warns.
- Routing and identity headers are reported as dropped at download time rather than silently discarded.
An entry with headersHelper must inline its full manifest
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.248
Separate failure code when a credential helper's token is rejected
Both mention header helper
-
v2.1.248
Credential-helper tokens suppress the MCP OAuth flow
Both mention header helper
-
v2.1.224
Plugins can be installed from an HTTPS zip archive
Both mention sha256