Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.280 Latest v2.1.285 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.285 ·

Git addresses for plugins and marketplaces are checked more strictly

Claude Code now refuses git addresses with certain odd characters when installing plugins or adding marketplaces, and explains which forms work

You'll notice Improvements
JSON All of v2.1.285
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PluginsArea: what it touches
ImprovementsKind: in v2.1.285,
ImprovementsSection of the release
What

Plugins and plugin marketplaces can be downloaded from git addresses. Claude Code now refuses a git address when it contains any of the following:

  • %00 anywhere in the address.
  • Square brackets that git could read as the name of a server.
  • A backslash before the first / of an http or https address.
  • :// inside a short-form address such as git@host:path.

When an address is refused, Claude Code says it is refusing to clone or refusing to query, and gives the reason. An error about an unreadable address now lists the forms Claude Code accepts. A file:// address that contains a drive letter gets an extra note that only applies on Windows.

The same check now covers downloading, looking up available versions, and asking a remote for its contents. It also covers two more places:

  • A marketplace given as a network git address. If the address fails the check, the marketplace is skipped.
  • Marketplaces listed from claude.ai. A git-based one only appears in the list if its address passes the check.
Why

Some unusual addresses can make git connect to a different server than the one the address seems to name. Refusing them closes that trick. A few odd addresses that used to work will now be refused.

See this entry in the whole of v2.1.285 →

Feedback