You'll noticeTier: how much it should matter to you
4Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
PluginsArea: what it touches
ImprovementsKind: in v2.1.286,
What probably matters to youSection of the release
What
Some plugins rely on other code packages, called dependencies. Claude Code now installs them from the plugin's package.json and its lockfile, a file that pins the exact version of every package.
The lockfile can be package-lock.json or a text bun.lock. A binary bun.lockb is not accepted.
The lockfile is checked strictly: packages must come from the registry, versions must be exact, integrity hashes must be present, and overrides and patchedDependencies are not allowed.
Installation runs npm ci --ignore-scripts or bun in a temporary folder, then moves the result into the plugin's folder.
When several lockfiles are present, bun.lockb is now checked after npm-shrinkwrap.json and package-lock.json, and the npm options come from one shared setting.
Failures appear as "Plugin dependency install failed", and skipped installs say "Skipped installing this plugin's dependencies:".
Why
Plugins that ship dependencies can have them installed without running any package scripts, and only from a lockfile that passes the checks. If a plugin has both bun and npm lockfiles, npm may now be picked.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Confirmed sinceAnthropic's documentation has since written up bun.lockb, on Plugin loading reference.* **`bun.lockb`**: Bun's binary lockfile can't be checked. Ship a text `bun.lock` or an npm lockfile insteadplugins/loadingsee the edit
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe arguments npm now receives are not shown, so it is not clear whether they are still `ci --ignore-scripts`.
Anthropic's documentation agreesAnthropic's documentation has since written up bun.lockb, on Plugin loading reference.