{"version":"2.1.286","anchor":"npm-plugin-sources-refuse-risky-tarball-links-and-unencrypte","canonical_anchor":"npm-plugin-sources-refuse-risky-tarball-links-and-unencrypte","heading":"Plugin installs from npm now refuse risky package links","tier":"notice","area":"Plugins","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/npm-plugin-sources-refuse-risky-tarball-links-and-unencrypte","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### Plugin installs from npm now refuse risky package links\n\nInstalling a plugin from npm now rejects invalid names, tarball links to code hosts, and unencrypted http registries\n\n**What**\n\nWhen you install a plugin from npm (the JavaScript package registry), Claude Code now checks the package before installing it. It refuses:\n\n- a package name that is not a valid npm package name\n\n- a tarball link (a direct link to a packed package file) that points at GitHub, GitLab, Bitbucket or SourceHut\n\n- a tarball link that contains `#` or whitespace\n\n- a tarball link using unencrypted `http` on a host other than your npm registry\n\n- a registry override that uses `http` and is not the default registry\n\nnpm also runs with git disabled during the install. If an install is refused, the error says why.\n\n**Why**\n\nThese checks make it harder for a plugin install to fetch code from somewhere unexpected or over an insecure connection. They can also make an install that used to work fail, so read the error message if one stops working.\n\n- Area: Plugins\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}