# How SHA Pinning in `marketplace.json` Prevents Supply Chain Attacks in Claude Plugins

> SHA pinning in marketplace.json stops supply chain attacks by linking plugins to immutable Git commit hashes. Ensure only vetted code installs even if repositories are compromised.

- Repository: [Anthropic/claude-plugins-community](https://github.com/anthropics/claude-plugins-community)
- Tags: how-to-guide
- Published: 2026-08-30

---

**SHA pinning in [`marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/marketplace.json) prevents supply chain attacks by binding each Claude plugin entry to an immutable Git commit hash, ensuring that only vetted code can be installed even if upstream repositories are compromised.**

The `anthropics/claude-plugins-community` repository maintains a decentralized marketplace of community-contributed Claude plugins, where security hinges on deterministic code verification rather than repository trust alone. By recording exact commit hashes in the manifest file, the system eliminates the risk of malicious updates slipping through after initial approval.

## Understanding the [`marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/marketplace.json) Manifest Structure

The [`.claude-plugin/marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/marketplace.json) file serves as the authoritative registry for all community-vetted plugins. Each entry contains critical metadata that defines the plugin's source of truth, including a **`url`** field pointing to the repository and a **`sha`** field containing the exact Git commit hash.

According to the source code in `anthropics/claude-plugins-community`, the manifest entry for the 0x plugin demonstrates this structure:

```json
{
  "name": "0x",
  "url": "https://github.com/0xProject/0x-ai.git",
  "sha": "0167bbb411cc972b966127d23c23de801061fa99"
}

```

This pinning mechanism appears at lines 17-20 of the manifest, establishing a cryptographic link between the marketplace entry and a specific point in the repository's history that has undergone security review.

## Three Layers of Supply Chain Protection

SHA pinning provides a defense-in-depth strategy against supply chain compromises through three distinct verification layers:

### Immutable Reference Verification

The **commit hash** acts as a unique fingerprint that cannot be altered without changing the hash itself. Even if attackers gain control of the upstream repository and push malicious commits to the default branch, the manifest continues to reference the original trusted commit. This prevents **repository takeover attacks** from automatically propagating to existing installations.

### Deterministic Retrieval Protocol

When installing a plugin, the Claude CLI performs a strict checkout operation against the pinned SHA. The installation process follows this verification sequence:

```bash

# 1. Clone the repository

git clone https://github.com/0xProject/0x-ai.git
cd 0x-ai

# 2. Explicitly checkout the pinned commit

git checkout 0167bbb411cc972b966127d23c23de801061fa99

```

If the checkout fails—whether because the commit was removed via force-push or the hash was tampered with—the installation aborts immediately. This ensures that **code-identity** rather than **code-location** determines what executes on the user's system.

### Verifiable Audit Trail

Security reviewers can independently verify plugin integrity by recomputing the hash of any checked-out code and comparing it against the manifest entry. This creates a **tamper-evident chain** between the review phase and deployment phase, making it impossible to substitute vetted code without detection.

## CLI Enforcement and Installation Security

The command-line interface implements strict SHA verification during the installation workflow. When a user executes:

```bash
claude plugin install 0x@claude-community

```

The CLI resolves the plugin name to its [`marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/marketplace.json) entry, extracts both the `url` and `sha` fields, and performs a shallow clone followed by an explicit detached-HEAD checkout at the specified commit. Any divergence between the expected SHA and the actual repository state triggers a hard failure, protecting users from **dependency confusion** and **branch hijacking** attacks.

The [`README.md`](https://github.com/anthropics/claude-plugins-community/blob/main/README.md) in the repository further documents that the marketplace operates as a **read-only verified registry**, meaning updates require new commit hashes to be submitted through the review pipeline rather than automatically syncing with repository HEAD.

## Summary

SHA pinning in [`marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/marketplace.json) establishes a robust security boundary for the Claude plugin ecosystem:

- **Immutable commits** prevent silent updates even if source repositories are compromised
- **Deterministic checkout** guarantees that only the exact vetted commit executes during installation
- **Cryptographic verification** creates an audit trail linking deployed code to reviewed code
- **Repository isolation** ensures that branch deletions or force-pushes cannot break the security model

## Frequently Asked Questions

### What happens if the pinned SHA is no longer available in the upstream repository?

If the commit hash referenced in [`marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/marketplace.json) has been removed via force-push or repository deletion, the installation will fail with a reference error. This failure is intentional—it prevents the system from falling back to untrusted code. Users must wait for maintainers to update the manifest with a new verified SHA from the current repository state.

### Can developers update their plugins without changing the SHA in the marketplace?

No. Because the manifest pins to a specific commit hash, any code changes require generating a new commit and submitting an update to the `anthropics/claude-plugins-community` repository with the new SHA. This creates a mandatory review gate where all updates undergo scrutiny before becoming available to users.

### How does SHA pinning protect against malicious maintainers?

If a plugin maintainer's account is compromised and an attacker pushes malicious code to the repository, existing users remain protected because their installations reference the previous trusted commit. The malicious code exists in the repository history but is never executed unless the marketplace manifest is explicitly updated to point at the new commit hash—a process that requires community review and approval.

### Is SHA pinning sufficient protection against all supply chain risks?

While SHA pinning eliminates risks from unauthorized repository changes and branch manipulation, it should be combined with additional measures like **signature verification** and **dependency auditing**. The pinned SHA ensures integrity of the primary plugin code, but downstream dependencies referenced by the plugin require their own verification mechanisms.