Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

Managed plugin marketplaces must be pinned to auto-install or be required

Admin marketplace entries asking for auto_install or required are treated as available, with a warning, unless pinned by commit SHA or manifestSha256

Group of 3 Use it now Improvements
JSON All of v2.1.281
Use it nowTier: how much it should matter to you
3Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
ImprovementsKind: in v2.1.281,
What probably matters to youSection of the release

What

Admins can list approved plugin marketplaces in allowedPluginMarketplaces and give each an installationPreference such as auto_install or required. An entry that asks for anything other than available is now shown as available, with a config warning, unless it is pinned to an exact version:

  • A url source needs manifestSha256, a fingerprint of the marketplace file.
  • Other sources need a full 40-character commit SHA in ref.

The settings documentation and the Cowork third-party config documentation now describe this. The Cowork documentation also changed in other ways:

  • The network allowlist text says an unreadable value counts as an empty list.
  • A new "End-user attribution" label appears.
  • The folder Path field is marked availableInVersion: "1.14271.0".

Why

Managed settings can no longer force-install plugins from a marketplace that is not pinned to an exact version. If you are an admin and your entry is unpinned, it stops auto-installing and only a config warning tells you. Add the pin to restore the behaviour.

See this entry in the whole of v2.1.281 →

Feedback