Skip to content

fix(plugin): bump both plugins to 0.2.0 so installs actually update - #333

Merged
ralyodio merged 1 commit into
mainfrom
bump-plugin-versions
Aug 9, 2026
Merged

fix(plugin): bump both plugins to 0.2.0 so installs actually update#333
ralyodio merged 1 commit into
mainfrom
bump-plugin-versions

Conversation

@ralyodio

@ralyodio ralyodio commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

Claude Code only pulls a new copy of a plugin when the plugin's own version moves:

"If set, users only receive updates when you bump this field."
https://code.claude.com/docs/en/plugins-reference#version-management

Both plugins have sat at 0.1.0 since they were created, through every change since — including v0.29.2, which rewrote every command file to carry the namespaced names. An existing install has been serving the old copy the whole time, so the surface people were told to use is the surface they didn't get. Shipping a moshcode release doesn't carry plugin edits; only this number does.

Both go to 0.2.0. The content they describe changed; the version now says so.

Stopping it happening again

version joins the catalog in src/plugins.mjs right next to commands — the thing an editor is already touching when they change a plugin — with the mechanism spelled out above it, and a test pinning the catalog to the manifest that ships.

I verified the guard fails when the two disagree rather than merely passing today:

✖ every plugin the marketplace lists exists, with a manifest and its commands
  crypto: the catalog and plugin.json disagree on the version

Also documented

claude plugin update <plugin>@moshcode — the step users need and the one nothing mentioned. moshcode upgrade updates the CLI and leaves installed plugins exactly where they were, which is not obvious.

Verification

Full suite: 1388 tests, 0 failures.

🤖 Generated with Claude Code

Claude Code only pulls a new copy of a plugin when the plugin's own version
moves: "If set, users only receive updates when you bump this field."
https://code.claude.com/docs/en/plugins-reference#version-management

Both plugins have sat at 0.1.0 since they were created, through every change
since — including v0.29.2, which rewrote every command file to carry the
namespaced names. An existing install has been serving the old copy the whole
time, so the surface people were told to use is the surface they did not get.
Shipping a moshcode release does not carry plugin edits; only this number does.

Both go to 0.2.0. The content they describe changed; the version now says so.

To stop it happening again, `version` joins the catalog next to `commands` —
the thing an editor is already touching when they change a plugin — with the
mechanism spelled out above it, and a test pinning the catalog to the manifest
that actually ships. Verified the guard fails when the two disagree rather than
merely passing today.

The README now documents `claude plugin update <plugin>@moshcode`, which is the
step users need and the one nothing mentioned: `moshcode upgrade` updates the
CLI and leaves installed plugins exactly where they were.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Aug 9, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

91 finding(s)

HIGH/CRITICAL: 2 | MEDIUM: 41 | LOW: 48

Severity Rule Location
HIGH manifest-typosquat apps/pwa/package.json:19
HIGH js-ssrf-outbound-request apps/pwa/public/sw.js:45
MEDIUM tls-verification-disabled apps/pwa/src/lib/moshpit-gateway.mjs:299
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:61
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:75
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:101
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:265
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:269
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:314
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:499
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:675
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:677
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:736
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:782
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:852
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:955
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:1063
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:1199
MEDIUM js-unescaped-html-sink apps/pwa/src/routes/moshpit.mjs:1419
MEDIUM js-dynamic-code-execution apps/pwa/test/apikey-mask.test.mjs:129
MEDIUM sql-template-interpolation apps/pwa/test/credits-webhook-event-match.test.mjs:111
MEDIUM sql-template-interpolation apps/pwa/test/credits-webhook-event-match.test.mjs:131
MEDIUM sql-template-interpolation apps/pwa/test/moshpit-terms.test.mjs:192
MEDIUM sql-template-interpolation src/dns.mjs:2439
MEDIUM sql-template-interpolation src/selfupdate.mjs:166
MEDIUM sql-template-interpolation src/selfupdate.mjs:170
MEDIUM sql-template-interpolation src/selfupdate.mjs:208
MEDIUM sql-template-interpolation src/selfupdate.mjs:209
MEDIUM insecure-temp-file test/dns-disable-restore.test.mjs:93
MEDIUM insecure-temp-file test/dns-disable-restore.test.mjs:310
MEDIUM insecure-temp-file test/plugins.test.mjs:126
MEDIUM insecure-temp-file test/pty.test.mjs:28
MEDIUM insecure-temp-file test/pty.test.mjs:31
MEDIUM insecure-temp-file test/pty.test.mjs:40
MEDIUM insecure-temp-file test/pty.test.mjs:42
MEDIUM insecure-temp-file test/pty.test.mjs:47
MEDIUM insecure-temp-file test/pty.test.mjs:48
MEDIUM insecure-temp-file test/pty.test.mjs:49
MEDIUM insecure-temp-file test/tabs.test.mjs:8
MEDIUM insecure-temp-file test/tabs.test.mjs:13
MEDIUM insecure-temp-file test/tabs.test.mjs:14
MEDIUM insecure-temp-file test/tabs.test.mjs:22
MEDIUM insecure-temp-file test/trust.test.mjs:240
LOW secret-generic-credential apps/pwa/test/apikey-bearer-scheme.test.mjs:30
LOW secret-generic-credential apps/pwa/test/apikey-mask.test.mjs:38
LOW secret-generic-credential apps/pwa/test/apikey-reveal.test.mjs:35
LOW secret-generic-credential apps/pwa/test/approvals-context.test.mjs:28
LOW secret-generic-credential apps/pwa/test/approvals-credits.test.mjs:28
LOW secret-generic-credential apps/pwa/test/approvals-notify.test.mjs:26
LOW secret-generic-credential apps/pwa/test/approvals-resolve-race.test.mjs:20

…and 41 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 0d26338 into main Aug 9, 2026
4 checks passed
@ralyodio ralyodio mentioned this pull request Aug 9, 2026
ralyodio added a commit that referenced this pull request Aug 9, 2026
Bump to v0.29.3, releasing the plugin version bump (#333).

Patch, and the moshcode half of it changes nothing: a README paragraph and a
catalog field. The part that matters is in the plugins, which now declare 0.2.0
instead of the 0.1.0 they had carried since creation — the number an engine
actually consults before pulling a new copy.

Until now, every plugin edit shipped in a moshcode release reached new installs
only. v0.29.2 rewrote every command file to carry the namespaced names, and no
existing install saw it. This is the release that makes those edits reachable,
via `claude plugin update <plugin>@moshcode`.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@ralyodio
ralyodio deleted the bump-plugin-versions branch August 9, 2026 00:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant