How the Nightly Sync Process for marketplace.json Works in Claude Plugins Community
The nightly sync process is an automated GitHub Actions workflow that runs at 07:23 UTC daily to pull the latest plugin metadata from Anthropic's internal review pipeline and update the public .claude-plugin/marketplace.json file.
The anthropics/claude-plugins-community repository serves as a read‑only mirror of Anthropic’s internal plugin marketplace. According to the source code analysis, the nightly synchronization ensures that the community has access to the latest validated plugin references without direct access to internal systems.
Architecture of the Nightly Sync Workflow
The synchronization is orchestrated through a scheduled GitHub Actions workflow defined in .github/workflows/bump-plugin-shas.yml. This automation acts as the public entry point that reflects changes from Anthropic’s internal review pipeline, maintaining the marketplace.json file as an accurate mirror of the upstream source.
Schedule and Trigger Configuration
The workflow operates on a strict cron schedule to guarantee daily updates. According to the workflow definition in .github/workflows/bump-plugin-shas.yml, the process triggers automatically at 07:23 UTC every day, with an optional manual dispatch for targeted updates.
on:
schedule:
- cron: '23 7 * * *' # Daily 07:23 UTC
workflow_dispatch:
inputs:
max_bumps:
description: Cap on plugins bumped this run
required: false
default: '30'
plugin:
description: Bump ONLY this plugin name (empty = all stale)
required: false
default: ''
The bump-plugin-shas Action
At the core of the nightly sync is the custom GitHub Action located at .github/actions/bump-plugin-shas. This action encapsulates the logic for reading the current marketplace manifest, detecting outdated plugin SHAs, validating new versions, and regenerating the marketplace.json file.
The 4-Step Synchronization Process
The nightly sync process for the marketplace.json file follows a strict sequence to ensure data integrity and prevent broken plugins from entering the mirror:
-
Load the freeze‑shas list – The workflow first retrieves a curated list of plugins known to be broken or temporarily frozen, ensuring these entries are excluded from the update cycle.
-
Execute the bump-plugin-shas action – The action reads the current
.claude-plugin/marketplace.json, identifies external entries with upstream commits that have moved past their pinned SHAs, validates each new SHA usingclaude plugin validate, and writes the updated entries back to the manifest. -
Commit changes and open pull requests – For each bumped plugin, the workflow commits the updated
marketplace.jsonand opens an individual pull request (one PR per plugin entry), enabling isolated review and rollback capabilities. -
Dispatch validation workflows – The workflow triggers the
validate-plugins.ymlworkflow for each generated pull request, ensuring the updated manifest passes the repository’s full validation suite before merging.
Configuration and Implementation Details
The implementation relies on specific input parameters passed to the bump action to control behavior and maintain repository stability.
Action Input Parameters
When the nightly sync executes, the workflow invokes the bump action with the following configuration, as defined in the workflow source:
- uses: ./.github/actions/bump-plugin-shas
id: bump
with:
marketplace-path: .claude-plugin/marketplace.json
max-bumps: ${{ inputs.max_bumps || '30' }}
freeze-shas: ${{ steps.freeze.outputs.list }}
only: ${{ inputs.plugin }}
pr-mode: per-entry
claude-cli-version: latest
- marketplace-path: Points to
.claude-plugin/marketplace.json, the target file for all updates. - max-bumps: Limits the number of plugins updated per run to prevent overwhelming the review queue (defaults to 30).
- freeze-shas: References the exclusion list generated in the first step.
- pr-mode: Configured as
per-entryto create individual pull requests for each plugin update. - claude-cli-version: Specifies the validation tool version to use during SHA verification.
Safety Mechanisms and Validation
The nightly sync process incorporates multiple safeguards to prevent corrupted or incompatible plugins from reaching the public mirror. The freeze-shas mechanism allows maintainers to temporarily exclude problematic plugins from the automatic update cycle, while the claude plugin validate command ensures each new SHA meets Anthropic’s validation standards before being written to marketplace.json.
After the bump action generates updates, the validate-plugins.yml workflow executes comprehensive checks on the modified manifest. This two-stage validation—first during SHA bumping and again via the dispatched workflow—ensures that the marketplace.json file remains functional and accurate.
Summary
- The nightly sync process for
marketplace.jsonis driven by thebump-plugin-shas.ymlworkflow, scheduled to run at 07:23 UTC daily. - The repository acts as a read‑only mirror, with the
.claude-plugin/marketplace.jsonfile assembled from Anthropic’s internal review pipeline. - The custom action at
.github/actions/bump-plugin-shashandles SHA detection, validation viaclaude plugin validate, and manifest regeneration. - Safety features include the freeze‑shas exclusion list and per‑entry pull request creation to isolate changes.
- The
validate-plugins.ymlworkflow provides secondary validation after each bump to ensure manifest integrity.
Frequently Asked Questions
What time does the marketplace.json nightly sync run?
The workflow triggers at 07:23 UTC every day according to the cron expression '23 7 * * *' defined in .github/workflows/bump-plugin-shas.yml. The repository also supports manual execution via workflow_dispatch for urgent updates or targeted plugin bumps.
Why does the sync create individual pull requests for each plugin?
The per-entry PR mode isolates each plugin update into its own pull request. This approach prevents a single broken plugin from blocking updates to other entries and allows maintainers to review, approve, or reject specific SHA bumps independently. The configuration parameter pr-mode: per-entry in the bump action enforces this behavior.
How does the sync prevent broken plugins from being published?
The process implements a freeze-shas exclusion list that filters out known broken plugins before the bump action executes. Additionally, each candidate SHA undergoes validation through the claude plugin validate command. Finally, the validate-plugins.yml workflow runs comprehensive checks on every generated pull request before merging changes to the main branch.
Can I manually trigger the marketplace.json sync for a specific plugin?
Yes. The workflow supports manual triggering through workflow_dispatch inputs. You can specify a single plugin name using the plugin input parameter, or adjust the max_bumps limit to control how many plugins update in a single run. This flexibility allows targeted updates without waiting for the scheduled 07:23 UTC execution.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →