Marketplace disabled in non-Community versions?

Hey there.

The Marketplace still exists in non-Community editions, but plugin installation/updates are manual (adding the plugin to your extensions/plugins directory of your SonarQube instance). The Marketplace still serves as a place to let users know about available plugins and updates to existing plugins installed on your instance.

Why the change? We know that the ability to extend SonarQube with plugins is an important feature, but these plugins are by definition not written by SonarSource and they can be a potential vector of vulnerability for SonarQube instances. To be clear, plugins are not vetted at each release by SonarSource for their security.

We want users to take it seriously and weigh potential impacts when they install/update a plugin, especially in a commercial setting.

Can you point to some of these issues? The changes should not have had an impact on them building/releasing their plugins.