Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.282 ·

Managed marketplace policy: empty allowlists enforced, settings passed to child processes, clearer errors

Admin blockedMarketplaces and strictKnownMarketplaces settings are enforced more consistently, including empty lists and child processes

Group of 5 You'll notice Improvements
JSON All of v2.1.282
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
ImprovementsKind: in v2.1.282,
ImprovementsSection of the release

What

Managed settings are settings an organization's administrator sets for everyone. Two of them control plugin marketplaces, the catalogs plugins are installed from: blockedMarketplaces blocks marketplace sources, and strictKnownMarketplaces allowlists the sources users can add and install from. This release changes how they are handled:

  • Settings validation now reports an error when blockedMarketplaces has entries but none are valid: "Every entry of "blockedMarketplaces" was invalid; none of them can be enforced until it is fixed." Before, only per-entry "Invalid entry was ignored" messages appeared.
  • An empty strictKnownMarketplaces array now counts as a restriction in force, as it already did for allowedMcpServers, allowedHttpHookUrls, httpHookAllowedEnvVars and availableModels.
  • When managed settings are inherited from a parent process, blockedMarketplaces is now copied through, and strictKnownMarketplaces joins allowedMcpServers and availableModels in being merged in when not already set.
  • strictKnownMarketplaces joins allowedMcpServers and availableModels on the list of keys only the admin or policy tier may set.
  • The fingerprint used to detect plugin policy changes now tells an unset allowlist or blocklist apart from an empty one, so adding an empty allowlist, which admits no marketplaces, counts as a change.
  • Reading a policy settings file now records whether it loaded (loaded, didNotLoad or absent) and whether it holds real policy content, so a file that fails to parse counts as not loaded instead of simply yielding no settings. A helper that copied a fixed set of keys out of the admin settings now returns all of them.

Why

An administrator who sets an empty marketplace allowlist to mean "none allowed" now gets that, including in sessions started by another Claude Code process. A blocklist that is entirely malformed is flagged instead of silently enforcing nothing.

Read from
Names in the bundleblockedMarketplaces
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up blockedMarketplaces, on Deploy managed settings. | `blockedMarketplaces` | An individual invalid entry is stripped and the valid subset is enforced. An entry that parses but can never match, such as a `hostPattern` regex that doesn't compile, is kept with a warning. It blocks nothing unt… managed-settings see the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agreesAnthropic's documentation has since written up blockedMarketplaces, on Deploy managed settings.

See this entry in the whole of v2.1.282 →

Feedback