What
A plugin marketplace is a catalogue listing plugins that can be installed into Claude Code. Two rules have been removed for listings whose installation is set to auto_install or required:
- Git sources no longer have to point at a full 40-character commit SHA, which is the unique ID of one exact version.
- URL sources no longer have to give a
manifestSha256, which is a fingerprint of the plugin's manifest file.
Another rule follows these two in the same place, but its contents are not shown.
Why
Marketplace listings that were rejected for missing an exact commit or manifest fingerprint may now pass these checks. Anyone who relied on those rules to pin automatically installed or required plugins to one exact version should check their listings.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
The rule that follows the removed ones is not shown, so it may bring in a different requirement in their place.