{"version":"2.1.281","anchor":"plugin-marketplace-schema-drops-shamanifest-hash-requiremen","canonical_anchor":"plugin-marketplace-schema-drops-shamanifest-hash-requiremen","heading":"Plugin marketplace schema drops SHA\/manifest hash requirements for auto_install\/required","tier":"notice","area":"Plugins","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/plugin-marketplace-schema-drops-shamanifest-hash-requiremen","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Plugin marketplace schema drops SHA\/manifest hash requirements for auto_install\/required\n\nMarketplace plugins set to auto_install or required no longer need a full commit SHA or a manifestSha256 hash\n\n**Unclear.** The rule that follows the removed ones is not shown, so it may bring in a different requirement in their place.\n\n**What**\n\nA plugin marketplace is a catalogue listing plugins that can be installed into Claude Code. Two rules have been removed for listings whose installation is set to `auto_install` or `required`:\n\n- Git sources no longer have to point at a full 40-character commit SHA, which is the unique ID of one exact version.\n\n- URL sources no longer have to give a `manifestSha256`, which is a fingerprint of the plugin's manifest file.\n\nAnother rule follows these two in the same place, but its contents are not shown.\n\n**Why**\n\nMarketplace listings that were rejected for missing an exact commit or manifest fingerprint may now pass these checks. Anyone who relied on those rules to pin automatically installed or required plugins to one exact version should check their listings.\n\n- Area: Plugins\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}