What
Admins can list approved plugin marketplaces in allowedPluginMarketplaces and give each an installationPreference such as auto_install or required. An entry that asks for anything other than available is now shown as available, with a config warning, unless it is pinned to an exact version:
- A
urlsource needsmanifestSha256, a fingerprint of the marketplace file. - Other sources need a full 40-character commit SHA in
ref.
The settings documentation and the Cowork third-party config documentation now describe this. The Cowork documentation also changed in other ways:
- The network allowlist text says an unreadable value counts as an empty list.
- A new "End-user attribution" label appears.
- The folder Path field is marked
availableInVersion: "1.14271.0".
Why
Managed settings can no longer force-install plugins from a marketplace that is not pinned to an exact version. If you are an admin and your entry is unpinned, it stops auto-installing and only a config warning tells you. Add the pin to restore the behaviour.