{"version":"2.1.282","anchor":"plugin-policy-fingerprint-now-tells-an-unset-marketplace-all","canonical_anchor":"warning-when-every-blockedmarketplaces-entry-is-invalid","heading":"Managed marketplace policy: empty allowlists enforced, settings passed to child processes, clearer errors","tier":"notice","area":"Managed Settings","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282\/e\/plugin-policy-fingerprint-now-tells-an-unset-marketplace-all","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282","markdown":"### Managed marketplace policy: empty allowlists enforced, settings passed to child processes, clearer errors\n\nAdmin blockedMarketplaces and strictKnownMarketplaces settings are enforced more consistently, including empty lists and child processes\n\n**Unclear.** It is not confirmed that this comparison is what makes Claude Code reload plugins.\n\n**What**\n\nManaged settings are settings an organization's administrator sets for everyone. Two of them control plugin marketplaces, the catalogs plugins are installed from: `blockedMarketplaces` blocks marketplace sources, and `strictKnownMarketplaces` allowlists the sources users can add and install from. This release changes how they are handled:\n\n- Settings validation now reports an error when `blockedMarketplaces` has entries but none are valid: \"Every entry of \"blockedMarketplaces\" was invalid; none of them can be enforced until it is fixed.\" Before, only per-entry \"Invalid entry was ignored\" messages appeared.\n\n- An empty `strictKnownMarketplaces` array now counts as a restriction in force, as it already did for `allowedMcpServers`, `allowedHttpHookUrls`, `httpHookAllowedEnvVars` and `availableModels`.\n\n- When managed settings are inherited from a parent process, `blockedMarketplaces` is now copied through, and `strictKnownMarketplaces` joins `allowedMcpServers` and `availableModels` in being merged in when not already set.\n\n- `strictKnownMarketplaces` joins `allowedMcpServers` and `availableModels` on the list of keys only the admin or policy tier may set.\n\n- The fingerprint used to detect plugin policy changes now tells an unset allowlist or blocklist apart from an empty one, so adding an empty allowlist, which admits no marketplaces, counts as a change.\n\n- Reading a policy settings file now records whether it loaded (`loaded`, `didNotLoad` or `absent`) and whether it holds real policy content, so a file that fails to parse counts as not loaded instead of simply yielding no settings. A helper that copied a fixed set of keys out of the admin settings now returns all of them.\n\n**Why**\n\nAn administrator who sets an empty marketplace allowlist to mean \"none allowed\" now gets that, including in sessions started by another Claude Code process. A blocklist that is entirely malformed is flagged instead of silently enforcing nothing.\n\n- Area: Managed Settings\n- Names: `strictKnownMarketplaces`, `blockedMarketplaces`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}