1
00:00:00,140 --> 00:00:04,360
You know that absolute brick wall you hit
when you're trying to push custom internal

2
00:00:04,420 --> 00:00:08,920
developer tooling into a locked down
corporate VPC, or maybe like,

3
00:00:08,979 --> 00:00:10,619
an air gapped CI CD runner?

4
00:00:11,800 --> 00:00:16,199
Git SSH ports are totally blocked,
external NPM registries are blocked,

5
00:00:16,539 --> 00:00:21,079
and you're basically stuck holding your
breath trying to get a basic script running.

6
00:00:21,405 --> 00:00:25,585
Oh yeah, I, I, I've lost entire afternoons
to that exact security lockdown.

7
00:00:26,224 --> 00:00:29,805
You end up having to request three
different firewall exceptions just to fetch a

8
00:00:29,824 --> 00:00:30,864
tiny helper package.

9
00:00:30,875 --> 00:00:31,275
Right!

10
00:00:31,291 --> 00:00:36,795
Well, the Anthropic team just tackled this
in Claude Code version 2.1.224.

11
00:00:36,891 --> 00:00:41,115
They added an archive plugin source, which
basically means you can now install

12
00:00:41,175 --> 00:00:46,315
plugins directly from a zip file over
HTTPS without needing git or npm on the

13
00:00:46,365 --> 00:00:47,435
machine at all.

14
00:00:47,697 --> 00:00:48,537
Wait, seriously?

15
00:00:49,236 --> 00:00:53,176
So no git binary, no npm CLI required on
the build host?

16
00:00:53,676 --> 00:00:55,896
You just drop in a raw ZIP archive link?

17
00:00:56,201 --> 00:00:56,961
Spot on, mate.

18
00:00:57,361 --> 00:01:02,002
You just jump into your dot claude slash
settings dot json file and set your plugin

19
00:01:02,141 --> 00:01:03,121
source to archive.

20
00:01:03,522 --> 00:01:07,681
Then you point the URL to something like
artifacts dot internal dot net slash

21
00:01:07,701 --> 00:01:11,021
plugins slash linter v2.0 dot zip.

22
00:01:11,282 --> 00:01:12,882
And what about the security side?

23
00:01:13,442 --> 00:01:17,083
If you're pulling arbitrary ZIP archives
over the network, how do you make sure

24
00:01:17,222 --> 00:01:19,982
nobody tampered with the file on the
internal artifact server?

25
00:01:20,042 --> 00:01:21,002
That's the clever bit.

26
00:01:21,114 --> 00:01:24,362
They included optional SHA 256 pinning.

27
00:01:24,655 --> 00:01:30,522
So right in that same JSON configuration,
you can pass a sha256 property with the

28
00:01:30,602 --> 00:01:34,922
exact cryptographic hash, like a3f5 and so
on.

29
00:01:35,162 --> 00:01:39,562
If the downloaded ZIP doesn't match that
exact hash, it won't execute.

30
00:01:39,651 --> 00:01:42,682
Complete supply chain verification built
right in.

31
00:01:42,906 --> 00:01:45,387
That is huge for enterprise compliance.

32
00:01:46,127 --> 00:01:50,526
But wait, are there any gotchas with how
the ZIP file itself has to be structured?

33
00:01:50,723 --> 00:01:52,462
A couple of strict rules, yeah.

34
00:01:53,242 --> 00:01:58,782
First off, the ZIP archive has to contain
a valid plugin dot json file right at the

35
00:01:58,862 --> 00:02:01,262
root or within the top level directory.

36
00:02:02,083 --> 00:02:08,122
Also, unencrypted plain HTTP endpoints are
rejected by default unless you explicitly

37
00:02:08,183 --> 00:02:13,262
override it, and if you download an
unpinned ZIP without supplying that SHA 256

38
00:02:13,322 --> 00:02:17,302
hash, Claude Code is gonna throw a
prominent security warning at you.

39
00:02:18,018 --> 00:02:18,517
Fair enough.

40
00:02:19,057 --> 00:02:23,458
Security teams would throw a fit if it
just silently downloaded unverified archives

41
00:02:23,497 --> 00:02:23,958
over the web.

42
00:02:24,000 --> 00:02:24,960
Exactly right.

43
00:02:25,140 --> 00:02:30,160
And, uh, speaking of enterprise stuff,
version 2.1.224 and

44
00:02:30,240 --> 00:02:35,360
2.1.225 brought a few other slick quality
of life tweaks too.

45
00:02:35,536 --> 00:02:41,040
Like, if you're running on AWS Bedrock,
there's a new ANTHROPIC BEDROCK REGION

46
00:02:41,120 --> 00:02:45,760
PREFIX environment variable so you can
handle cross region inference profiles much

47
00:02:45,817 --> 00:02:46,240
easier.

48
00:02:46,369 --> 00:02:47,629
Oh, nice!

49
00:02:47,649 --> 00:02:50,609
And didn't they fix up the gateway spend
limit notifications as well?

50
00:02:50,846 --> 00:02:51,526
Yeah, they did!

51
00:02:52,407 --> 00:02:56,866
Instead of just a generic warning, the
gateway spend limit alerts now show your

52
00:02:56,986 --> 00:03:00,806
exact dollar cap and the exact reset time
down to the minute.

53
00:03:01,386 --> 00:03:05,646
Plus, there's a neat interactive cancel
and confirm prompt whenever you paste

54
00:03:05,726 --> 00:03:09,686
modified text back into the terminal, so
you don't accidentally run runaway

55
00:03:09,726 --> 00:03:10,246
commands.

56
00:03:11,316 --> 00:03:15,897
Man, not having to install NPM on a
barebones container just to run a Claude plugin

57
00:03:15,936 --> 00:03:18,637
is going to save so many devops headaches.

58
00:03:18,696 --> 00:03:19,196
Good stuff.

