Skip to content

[Bug] autoUpdate on extraKnownMarketplaces entry does not trigger plugin update at session start #4465

Description

@caleb-collar

Describe the bug

The changelog for 1.0.79 documents:

Set "autoUpdate": true on an extraKnownMarketplaces entry in your user settings to auto-update its plugins at session start

This does not happen. With autoUpdate: true set on an extraKnownMarketplaces entry and an installed plugin from that marketplace deliberately pinned to an older version (both in ~/.copilot/config.json and the cached .plugin/plugin.json/.claude-plugin/plugin.json), starting a brand-new CLI session (full process relaunch, not /restart) does not check for or apply an update. No log line referencing a plugin/marketplace update check appears anywhere in the session's debug log at startup.

Separately, when the update mechanism is triggered manually (copilot plugin update <name>), it worked correctly once a Windows file-lock (held by lingering VS Code / github-copilot-sdk background processes on the shared ~/.copilot/installed-plugins cache) was cleared. That confirms the underlying reinstall codepath is functional — the gap is specifically that automatic checking/triggering at session start never occurs, and (separately) that a locked-file failure during any such attempt would fail silently with no user-visible warning.

Steps to reproduce

  1. In user settings (~/.copilot/settings.json or via /settings), add/confirm an extraKnownMarketplaces entry with "autoUpdate": true, e.g.:
    "extraKnownMarketplaces": {
      "my-marketplace": {
        "source": { "source": "git", "url": "https://example.com/my-org/my-plugins" },
        "autoUpdate": true
      }
    }
  2. Have a plugin from that marketplace installed and enabled (e.g. version 0.2.0).
  3. Manually edit ~/.copilot/config.json (installedPlugins[].version) and the plugin's cached manifest (~/.copilot/installed-plugins/<marketplace>/<plugin>/.claude-plugin/plugin.json version field) down to an older version (e.g. 0.1.0), leaving source_sha untouched.
  4. Fully quit the CLI process (not /restart — a true new process launch) and start copilot again.
  5. Inspect ~/.copilot/config.json and the cached plugin.json again, and check ~/.copilot/logs/process-*.log for the new session for any plugin/marketplace update activity.

Expected behavior

On session start, the CLI should detect the installed plugin version is behind the marketplace's current version and automatically reinstall/update it (per the documented 1.0.79 changelog entry), updating config.json, the cached manifest, and installed_at.

Actual behavior

  • The plugin version in config.json and the cached manifest remains at the older pinned version after a full CLI relaunch.
  • installed_at timestamp is unchanged, confirming no reinstall attempt occurred.
  • The startup debug log shows no entries related to checking plugin/marketplace versions or auto-updating — it goes directly from initialization to loading/activating the existing cached plugins:
    ...Init suggestion check completed
    ...Loaded MCP config from installed plugins: 3 server(s): ...
    ...Plugin activation [agents]: fingerprint=..., plugins=11, loaded=14
    
  • Running copilot plugin update <plugin-name> manually does work once file locks are cleared, confirming the reinstall codepath itself is functional — it's just never invoked automatically at session start as documented.

Environment

  • GitHub Copilot CLI: 1.0.79
  • OS: Windows 11
  • Node.js: v24.18.1
  • Marketplace: private git-hosted extraKnownMarketplaces entry with autoUpdate: true

Additional context

While testing this, we also observed that a Windows file-lock on the shared ~/.copilot/installed-plugins/<marketplace>/<plugin> cache directory (held by lingering github-copilot-sdk background processes, e.g. from VS Code's Copilot extension) causes a manual copilot plugin update <plugin> to fail with Failed to install plugin: Access is denied. (os error 5). If the same lock were encountered during an automatic session-start check, it would likely fail silently with no user-facing message — worth surfacing a warning/error in that case rather than no-op.


🤖 This issue was drafted with assistance from GitHub Copilot CLI.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:configurationConfig files, instruction files, settings, and environment variablesarea:pluginsPlugin system, marketplace, hooks, skills, extensions, and custom agents

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions