What probably matters to youSection of the release
Unclear The finding does not say what the "End-user attribution" label describes.
What
Admins can list approved plugin marketplaces in allowedPluginMarketplaces and give each an installationPreference such as auto_install or required. An entry that asks for anything other than available is now shown as available, with a config warning, unless it is pinned to an exact version:
A url source needs manifestSha256, a fingerprint of the marketplace file.
Other sources need a full 40-character commit SHA in ref.
The settings documentation and the Cowork third-party config documentation now describe this. The Cowork documentation also changed in other ways:
The network allowlist text says an unreadable value counts as an empty list.
A new "End-user attribution" label appears.
The folder Path field is marked availableInVersion: "1.14271.0".
Why
Managed settings can no longer force-install plugins from a marketplace that is not pinned to an exact version. If you are an admin and your entry is unpinned, it stops auto-installing and only a config warning tells you. Add the pin to restore the behaviour.