Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.284 ·

Plugin marketplace sources can now have credentials removed and odd URLs refused

Claude Code now has a check that strips usernames, passwords and headers from plugin marketplace sources and refuses suspicious URLs

You'll notice Improvements
JSON All of v2.1.284
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PluginsArea: what it touches
ImprovementsKind: in v2.1.284,
ImprovementsSection of the release
What

A plugin marketplace is a place Claude Code can find and install plugins (add-on packages) from. Each marketplace has a source, which says where it lives: a web address, a git repository, an npm package, or an entry in your settings.

Claude Code now has a check that cleans up these sources. It removes the username and password from a source's web address and drops any headers or headersHelper entries. For npm tarball addresses (a direct download link for an npm package), it also removes the username, password, query string and anything after a #.

The check refuses a source when:

  • its web address has a query string (the part after ?) or a fragment (the part after #)
  • its path does not match what is expected
  • it contains an @ or # whose meaning is ambiguous
  • it is a settings plugin whose source is a command
Why

This looks designed to keep marketplace credentials out of a form that could be stored or passed along to others.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear when Claude Code runs this check, for example when saving or when displaying marketplace sources.

See this entry in the whole of v2.1.284 →

Feedback