Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

Plugin marketplace schema drops SHA/manifest hash requirements for auto_install/required

Marketplace plugins set to auto_install or required no longer need a full commit SHA or a manifestSha256 hash

Entry
JSON All of v2.1.281
EntryKind: in v2.1.281,
ChangesSection of the release
What

A plugin marketplace is a catalogue listing plugins that can be installed into Claude Code. Two rules have been removed for listings whose installation is set to auto_install or required:

  • Git sources no longer have to point at a full 40-character commit SHA, which is the unique ID of one exact version.
  • URL sources no longer have to give a manifestSha256, which is a fingerprint of the plugin's manifest file.

Another rule follows these two in the same place, but its contents are not shown.

Why

Marketplace listings that were rejected for missing an exact commit or manifest fingerprint may now pass these checks. Anyone who relied on those rules to pin automatically installed or required plugins to one exact version should check their listings.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe rule that follows the removed ones is not shown, so it may bring in a different requirement in their place.

See this entry in the whole of v2.1.281 →

Feedback