{"version":"2.1.288","anchor":"plugin-sha-pin-validation-and-verification-reworked","canonical_anchor":"plugin-sha-pin-validation-and-verification-reworked","heading":"Pinned plugin commits must be full commit hashes","tier":"notice","area":"Plugins","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/plugin-sha-pin-validation-and-verification-reworked","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Pinned plugin commits must be full commit hashes\n\nA plugin pinned to a commit must now give the full 40- or 64-character hash; short hashes are rejected\n\n**What**\n\nA plugin listing can pin the plugin to one exact version of its code by giving a commit hash, a long code made of the characters 0 to 9 and a to f that names a single version. That pin must now be a full hash of 40 or 64 characters. Anything else is rejected with the message \"must be a full commit hash (40 or 64 hex digits)\".\n\nBefore, the only rule was that the pin could not start with \"-\". The step that checks the downloaded code really matches the pin can now check a named branch or tag, instead of always checking the latest commit that was downloaded.\n\n**Why**\n\nA plugin listing that pins a shortened hash will now fail to install, so anyone publishing plugins should write out the full hash.\n\n- Area: Plugins\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: yes"}