Follow Discord
Sweep 01 Oct 2026 · 17:27Z Build v2.1.287 508 read Stable v2.1.285 Latest v2.1.287 Next v2.1.287 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.286 ·

Plugin dependencies installed from checked lockfiles with scripts turned off

Claude Code installs plugin dependencies from a checked package-lock.json or bun.lock using npm ci --ignore-scripts or bun, preferring npm lockfiles

Group of 2 You'll notice New Features
JSON All of v2.1.286
You'll noticeTier: how much it should matter to you
4Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
PluginsArea: what it touches
New FeaturesKind: in v2.1.286,
What probably matters to youSection of the release

What

Some plugins rely on other code packages, called dependencies. Claude Code now installs them from the plugin's package.json and its lockfile, a file that pins the exact version of every package.

  • The lockfile can be package-lock.json or a text bun.lock. A binary bun.lockb is not accepted.
  • The lockfile is checked strictly: packages must come from the registry, versions must be exact, integrity hashes must be present, and overrides and patchedDependencies are not allowed.
  • Installation runs npm ci --ignore-scripts or bun in a temporary folder, then moves the result into the plugin's folder.
  • When several lockfiles are present, bun.lockb is now checked after npm-shrinkwrap.json and package-lock.json, and the npm options come from one shared setting.
  • Failures appear as "Plugin dependency install failed", and skipped installs say "Skipped installing this plugin's dependencies:".

Why

Plugins that ship dependencies can have them installed without running any package scripts, and only from a lockfile that passes the checks. If a plugin has both bun and npm lockfiles, npm may now be picked.

Read from
Names in the bundlepackage-lock.jsonbun.lock
What the documentation says
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up package-lock.json, on Plugin loading reference. | `npm-shrinkwrap.json` or `package-lock.json` | npm | plugins/loading see the edit
Confirmed since Anthropic's documentation has since written up bun.lock, on Plugin loading reference. | `bun.lock` | Bun | plugins/loading see the edit
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is unclear what starts this install and whether anything gates it.
Anthropic's documentation agreesAnthropic's documentation has since written up bun.lock, on Plugin loading reference.

See this entry in the whole of v2.1.286 →

Feedback