You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
PluginsArea: what it touches
ImprovementsKind: in v2.1.287,
ImprovementsSection of the release
What
A lockfile is a file that pins the exact versions of the packages a plugin depends on. Installing a plugin's dependencies now refuses the plugin in these cases:
it ships a yarn or pnpm lockfile, which plugin installs do not support
it ships a binary bun.lockb, which cannot be checked; the error asks for a text bun.lock instead
npm or bun is not installed on the machine
When the install succeeds, Claude Code builds the node_modules folder in a separate staging copy first. It then moves the folder into place, checking that the folder was not swapped out along the way.
Why
Plugin authors need to ship a supported text lockfile, or the plugin will not install. A missing npm or bun is now reported as a clear refusal.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear whether this check runs on every plugin install.