- classifyInstallTarget skips known npm dist-tags (latest, next, beta,
etc.) and semver-like strings before checking marketplace names
- updateMarketplace throws if fetched catalog name differs from the
registered name, preventing stale data on upstream renames
- parseMarketplaceCatalog validates variant-specific required fields
(github.repo, url.url, git-subdir.url+path, npm.package) at parse
time instead of deferring to install-time crashes