{"version":"2.1.287","anchor":"dependency-install-check-for-plugins-lockfile-support","canonical_anchor":"dependency-install-check-for-plugins-lockfile-support","heading":"Plugins with yarn, pnpm or binary bun lockfiles are refused at install","tier":"notice","area":"Plugins","scope":null,"heads_up":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287\/e\/dependency-install-check-for-plugins-lockfile-support","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287","markdown":"### Plugins with yarn, pnpm or binary bun lockfiles are refused at install\n\nInstalling a plugin's dependencies now fails for yarn or pnpm lockfiles, a binary `bun.lockb`, or when npm or bun is missing\n\n**Unclear.** It is not clear whether this check runs on every plugin install.\n\n**What**\n\nA lockfile is a file that pins the exact versions of the packages a plugin depends on. Installing a plugin's dependencies now refuses the plugin in these cases:\n\n- it ships a yarn or pnpm lockfile, which plugin installs do not support\n\n- it ships a binary `bun.lockb`, which cannot be checked; the error asks for a text `bun.lock` instead\n\n- npm or bun is not installed on the machine\n\nWhen the install succeeds, Claude Code builds the `node_modules` folder in a separate staging copy first. It then moves the folder into place, checking that the folder was not swapped out along the way.\n\n**Why**\n\nPlugin authors need to ship a supported text lockfile, or the plugin will not install. A missing npm or bun is now reported as a clear refusal.\n\n- Area: Plugins\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 2\/5"}