You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PluginsArea: what it touches
ImprovementsKind: in v2.1.288,
ImprovementsSection of the release
What
A plugin listing can pin the plugin to one exact version of its code by giving a commit hash, a long code made of the characters 0 to 9 and a to f that names a single version. That pin must now be a full hash of 40 or 64 characters. Anything else is rejected with the message "must be a full commit hash (40 or 64 hex digits)".
Before, the only rule was that the pin could not start with "-". The step that checks the downloaded code really matches the pin can now check a named branch or tag, instead of always checking the latest commit that was downloaded.
Why
A plugin listing that pins a shortened hash will now fail to install, so anyone publishing plugins should write out the full hash.