Follow Discord
Sweep 01 Oct 2026 · 17:27Z Build v2.1.287 508 read Stable v2.1.285 Latest v2.1.287 Next v2.1.287 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.287 ·

Plugins with yarn, pnpm or binary bun lockfiles are refused at install

Installing a plugin's dependencies now fails for yarn or pnpm lockfiles, a binary bun.lockb, or when npm or bun is missing

You'll notice Improvements
JSON All of v2.1.287
You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
PluginsArea: what it touches
ImprovementsKind: in v2.1.287,
ImprovementsSection of the release
What

A lockfile is a file that pins the exact versions of the packages a plugin depends on. Installing a plugin's dependencies now refuses the plugin in these cases:

  • it ships a yarn or pnpm lockfile, which plugin installs do not support
  • it ships a binary bun.lockb, which cannot be checked; the error asks for a text bun.lock instead
  • npm or bun is not installed on the machine

When the install succeeds, Claude Code builds the node_modules folder in a separate staging copy first. It then moves the folder into place, checking that the folder was not swapped out along the way.

Why

Plugin authors need to ship a supported text lockfile, or the plugin will not install. A missing npm or bun is now reported as a clear refusal.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear whether this check runs on every plugin install.

See this entry in the whole of v2.1.287 →

Feedback