48763a4d01
Teknium's ruling: catalog plugins do not need the 2-week maturity window, but they may not ship an in-app updater that downloads and replaces their own files, because that makes the reviewed SHA pin decorative. Rule 3 in the README and item 5 on the docs page now say so, and plugin-catalog-ci fails an entry whose catalog build both fetches from GitHub releases/raw and writes or renames plugin files (either half alone is allowed).