Cached plugin installs are re-verified against trusted roots before being reused.
What's wrong with this entry?
Resolving a plugin from a marketplace now re-derives the trusted roots and rejects an install path it considers suspect before treating the cached copy as current. For plugins served in place from a command-provided source, it confirms the source really is a directory of links rather than accepting a path that merely looks like one.
- when the cached copy cannot be safely reused, the error says the plugin is served in place from a path that could not be resolved or no longer matches its cached links
- always on; there is no setting to skip the extra checks
it is served in place from
Strings lifted out of the shipped bundle, so the claim above can be checked against them.