Publishing guide
Verification
Verified plugins show the Verified badge, are updated automatically for users, and every version is reviewed by a person before users get it.
Requirements
- The plugin has at least one published version.
- Your GitHub account or organization is at least 90 days old.
- The default branch is protected: no force pushes, no deletion.
- Release tags (
v*) are protected: only maintainers can create them, and nobody can move or delete them. - Immutable releases are turned on.
- Two-factor authentication is required in your organization, or every maintainer confirms they use it.
- You have a security contact: a
SECURITY.mdor GitHub's private vulnerability reporting. - You accept the publisher policy.
- An administrator has read the full source of your current version.
Ask for verification
Open a Verification issue in the registry. The issue lists the requirements as a checklist; an administrator checks each one with you.
Keeping it
The hub checks the requirements it can see every night. If one stops being met, an administrator contacts you. Verification can be withdrawn, for example if a security report goes unanswered for 14 days.