{"version":"2.1.281","anchor":"admin-marketplace-allowlist-installationpreference-is-clamp","canonical_anchor":"admin-marketplace-allowlist-installationpreference-is-clamp","heading":"Managed plugin marketplaces must be pinned to auto-install or be required","tier":"use","area":"Plugins","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/admin-marketplace-allowlist-installationpreference-is-clamp","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Managed plugin marketplaces must be pinned to auto-install or be required\n\nAdmin marketplace entries asking for auto_install or required are treated as available, with a warning, unless pinned by commit SHA or manifestSha256\n\n**What**\n\nAdmins can list approved plugin marketplaces in `allowedPluginMarketplaces` and give each an `installationPreference` such as `auto_install` or `required`. An entry that asks for anything other than `available` is now shown as `available`, with a config warning, unless it is pinned to an exact version:\n\n- A `url` source needs `manifestSha256`, a fingerprint of the marketplace file.\n\n- Other sources need a full 40-character commit SHA in `ref`.\n\nThe settings documentation and the Cowork third-party config documentation now describe this. The Cowork documentation also changed in other ways:\n\n- The network allowlist text says an unreadable value counts as an empty list.\n\n- A new \"End-user attribution\" label appears.\n\n- The folder Path field is marked `availableInVersion: \"1.14271.0\"`.\n\n**Why**\n\nManaged settings can no longer force-install plugins from a marketplace that is not pinned to an exact version. If you are an admin and your entry is unpinned, it stops auto-installing and only a config warning tells you. Add the pin to restore the behaviour.\n\n- Area: Plugins\n- Names: `allowedPluginMarketplaces`, `installationPreference`\n- Tier: Use it now\n- Useful: 3\/5\n- Signal: 2\/5"}