You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PluginsArea: what it touches
ImprovementsKind: in v2.1.285,
ImprovementsSection of the release
What
Some plugins ask for settings when you install them, including secrets such as keys, which are kept in pluginSecrets. This release changes which plugins those saved values are gathered from:
Dependency chain: a plugin that depends on other plugins now combines secrets from every plugin in that chain, plus its own. Before, it combined only one parent's secrets with its own.
Renamed plugins: when a plugin's options and secrets are saved, values stored under the plugin's older, replaced ids are merged into its current id, and the old entries are removed. The plugin's mcpServers settings are merged the same way. Before, values were written only under the single current id.
If saving these sensitive options fails, Claude Code reports "Failed to save sensitive plugin options for" the plugin.
Why
A plugin that depends on others can now see secrets set on more of the plugins it builds on. A plugin that has been renamed should keep the configuration you already gave it instead of asking again or losing it.