<div dir="ltr"><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">Hi All</div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">Yes the plugin reviewers are inundated, I have many sleepless nights worrying about what executable software is being distributed to users computers and I would also like to change the situation. Lova and I have been working to try to add better checks and compliance checking in an automated, and we were planning on more in this vein, like adding a tagging system e.g. AI Coded, AI Assited, Trusted User, Know Issues, etc that we can apply to plugins. One of the bigger changes we have made recently is restricting the ability to self approve plugins, but that just puts more burden on the plugin reviewers.</div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">I also look forward to chatting about this at the user conference. One of the things that Lova and I are working on is a new SSO / Keycloak system with a web of trust concept, and I have been playing with ideas of how we can build a social graph system (sorry to sound like facebook) where we accummulate trust to gain rights like publishing plugins autonomously, and also cascade remove trust to create a strong incentive for a community member to work hard to keep their trusted status. But we need to figure out the details and test it etc.</div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">On the other hand, it is really trivial to create your own plugins repo and publish your own plugins there, so maybe we should focus rather on creating a repository directory and help users discover plugins, but put up a 'there be dragons' sign when they are leaving our small, curated collection of plugins.</div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">Look forward to chatting about it next week...</div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">Regards</div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">Tim</div><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small"><br></div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Wed, Sep 30, 2026 at 4:07 PM Raymond Nijssen via QGIS-Developer <<a href="mailto:qgis-developer@lists.osgeo.org">qgis-developer@lists.osgeo.org</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi, I also agree the plugin policies need to be changed. Also check the <br>
email from Stefano earlier today. I'm really feeling sorry for the ones <br>
who are dealing with all the new plugins.<br>
<br>
Just some ideas from my side:<br>
<br>
More plugin metadata:<br>
* description where to find the plugin in QGIS<br>
* plugin language(s)<br>
* code is generated by AI<br>
* plugin needs a (paid) account to function<br>
* plugin has software dependencies<br>
* a category?<br>
<br>
Detect some IMHO real bad quality signs:<br>
* Icon is still the default plugin builder icon (or even missing)<br>
* Dialogs are not responsive<br>
<br>
Some quality constraints for uploading to the plugin repository could be:<br>
* Plugin should use as much as possible the QGIS functionality. For <br>
example, the plugin should not read or write a shapefile from disk, but <br>
work on vector layers. QGIS can read and write the shapefile (an many more).<br>
* Plugin must be in English, translations can be done by Qt tr() function.<br>
* If possible, data manipulations must be through processing algorithms<br>
* All web traffic must be using QgsNetworkAccessManager (to make <br>
debugging possible)<br>
<br>
We could also consider having a paid repo, with paid staff keeping it <br>
clean, high quality and safe. We could also make it easier to add/find <br>
other, less strictly maintained, repos.<br>
<br>
Love to discuss this next week in Laax!<br>
<br>
Raymond<br>
<br>
<br>
<br>
On 9/30/26 13:59, Régis Haubourg via QGIS-Developer wrote:<br>
> Hi, I agree that our community repository is really large now and the <br>
> world has changed. What should be the direction we should take according <br>
> to you? Something like an official repo, with a real security triage, <br>
> and a filter of really up to date and active tools?<br>
> And besides this, community repositories, not activated by default ? <br>
> Thanks for your ideas, user conference and community meeting is next <br>
> week and a dedicated session would be wonderful<br>
> Cheers<br>
> Régis<br>
> <br>
> <br>
> On 30/09/2026 13:31, Nicolas Godet via QGIS-Developer <qgis- <br>
> <a href="mailto:developer@lists.osgeo.org" target="_blank">developer@lists.osgeo.org</a>> wrote:<br>
>> Dear all,<br>
>><br>
>> I can’t agree more on the fact that the plugin repo has become a wild <br>
>> jungle with less and less interest in digging into it to find an <br>
>> innovative one.<br>
>> A few years ago, I spent a few minutes each week looking at each new <br>
>> plugin (because there were only ten or so). Now, I don’t look at new <br>
>> plugins anymore because there are too many of them and most of them <br>
>> are a duplicate of another plugin or, even worse, of a core feature.<br>
>><br>
>> I think new rules should be put in place or at least a way to <br>
>> distinguish good, community-approved plugins from the nonsense garbage <br>
>> in the quest for likes for their LinkedIn post.<br>
>><br>
>> Kind regards,<br>
>> Nicolas<br>
>><br>
>> > Le 29 sept. 2026 à 17:45, Stefano Campus via QGIS-Developer <qgis- > <br>
>> <a href="mailto:developer@lists.osgeo.org" target="_blank">developer@lists.osgeo.org</a>> a écrit :<br>
>> ><br>
>> > <br>
>> > Good morning,<br>
>> > a few days ago, a plugin [1] was released that is a fork of an > <br>
>> existing plugin which had been updated (without the original plugin > <br>
>> author being notified) to QGIS 4.<br>
>> > The GitHub repository has issues disabled, so it is not possible to <br>
>> > report bugs that are present.<br>
>> ><br>
>> > But shouldn’t it be mandatory to have issue reporting enabled?<br>
>> ><br>
>> > Furthermore, the proliferation of plugins makes it difficult to find <br>
>> > the truly innovative ones.<br>
>> > So we see plugins that replicate core functions, perhaps giving them <br>
>> a > more appealing user interface<br>
>> ><br>
>> > Where can I report this to the team that coordinates the plugins?<br>
>> > Do you think we should report these anomalies?<br>
>> ><br>
>> > Many thanks<br>
>> ><br>
>> > stefano<br>
>> ><br>
>> > [1] <a href="https://github.com/veogeo/go3streetview" rel="noreferrer" target="_blank">https://github.com/veogeo/go3streetview</a> <<a href="https://github.com/" rel="noreferrer" target="_blank">https://github.com/</a> > <br>
>> veogeo/go3streetview><br>
>> > _______________________________________________<br>
>> > QGIS-Developer mailing list<br>
>> > <a href="mailto:QGIS-Developer@lists.osgeo.org" target="_blank">QGIS-Developer@lists.osgeo.org</a><br>
>> > List info: <a href="https://lists.osgeo.org/mailman/listinfo/qgis-developer" rel="noreferrer" target="_blank">https://lists.osgeo.org/mailman/listinfo/qgis-developer</a><br>
>> > Unsubscribe: <a href="https://lists.osgeo.org/mailman/listinfo/qgis-developer" rel="noreferrer" target="_blank">https://lists.osgeo.org/mailman/listinfo/qgis-developer</a><br>
>><br>
>> _______________________________________________<br>
>> QGIS-Developer mailing list<br>
>> <a href="mailto:QGIS-Developer@lists.osgeo.org" target="_blank">QGIS-Developer@lists.osgeo.org</a><br>
>> List info: <a href="https://lists.osgeo.org/mailman/listinfo/qgis-developer" rel="noreferrer" target="_blank">https://lists.osgeo.org/mailman/listinfo/qgis-developer</a><br>
>> Unsubscribe: <a href="https://lists.osgeo.org/mailman/listinfo/qgis-developer" rel="noreferrer" target="_blank">https://lists.osgeo.org/mailman/listinfo/qgis-developer</a><br>
>><br>
> _______________________________________________<br>
> QGIS-Developer mailing list<br>
> <a href="mailto:QGIS-Developer@lists.osgeo.org" target="_blank">QGIS-Developer@lists.osgeo.org</a><br>
> List info: <a href="https://lists.osgeo.org/mailman/listinfo/qgis-developer" rel="noreferrer" target="_blank">https://lists.osgeo.org/mailman/listinfo/qgis-developer</a><br>
> Unsubscribe: <a href="https://lists.osgeo.org/mailman/listinfo/qgis-developer" rel="noreferrer" target="_blank">https://lists.osgeo.org/mailman/listinfo/qgis-developer</a><br>
<br>
_______________________________________________<br>
QGIS-Developer mailing list<br>
<a href="mailto:QGIS-Developer@lists.osgeo.org" target="_blank">QGIS-Developer@lists.osgeo.org</a><br>
List info: <a href="https://lists.osgeo.org/mailman/listinfo/qgis-developer" rel="noreferrer" target="_blank">https://lists.osgeo.org/mailman/listinfo/qgis-developer</a><br>
Unsubscribe: <a href="https://lists.osgeo.org/mailman/listinfo/qgis-developer" rel="noreferrer" target="_blank">https://lists.osgeo.org/mailman/listinfo/qgis-developer</a><br>
</blockquote></div><div><br clear="all"></div><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature"><div dir="ltr"><br><div><div style="color:rgb(34,34,34)">Tim Sutton</div><div style="color:rgb(34,34,34)"><b>Kartoza Cofounder<br></b><span style="color:rgb(32,33,36);text-align:center">Tim is a member of the QGIS Project Steering Committee</span><b><br></b></div><div style="color:rgb(34,34,34)"><b><br></b></div><div style="color:rgb(34,34,34)"><b>E </b>:<b> </b><a href="mailto:tim@kartoza.com" style="color:rgb(17,85,204)" target="_blank">tim@kartoza.com</a> <b>W</b> : <a href="http://kartoza.com/" style="color:rgb(17,85,204)" target="_blank">kartoza.com</a><br></div><div style="color:rgb(34,34,34)"><br></div><div style="color:rgb(34,34,34)"><div><i><img src="https://kartoza.com/files/KartozaEmailSignature.gif" width="420" height="77"><br></i></div><div><i><br></i></div><div><i>This email and any attachments are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you </i><div><i>have received this email in error, please notify the sender immediately and delete it from your system. Unauthorised use, disclosure, or copying</i></div><div><i>of the contents is prohibited.</i></div></div></div></div></div></div>