[QGIS-Developer] Are there any real mandatory rules for publishing a plugin?
Tim Sutton
tim at kartoza.com
Wed Sep 30 09:21:34 PDT 2026
Hi All
Yes the plugin reviewers are inundated, I have many sleepless nights
worrying about what executable software is being distributed to users
computers and I would also like to change the situation. Lova and I have
been working to try to add better checks and compliance checking in an
automated, and we were planning on more in this vein, like adding a tagging
system e.g. AI Coded, AI Assited, Trusted User, Know Issues, etc that we
can apply to plugins. One of the bigger changes we have made recently is
restricting the ability to self approve plugins, but that just puts more
burden on the plugin reviewers.
I also look forward to chatting about this at the user conference. One of
the things that Lova and I are working on is a new SSO / Keycloak system
with a web of trust concept, and I have been playing with ideas of how we
can build a social graph system (sorry to sound like facebook) where we
accummulate trust to gain rights like publishing plugins autonomously, and
also cascade remove trust to create a strong incentive for a community
member to work hard to keep their trusted status. But we need to figure out
the details and test it etc.
On the other hand, it is really trivial to create your own plugins repo and
publish your own plugins there, so maybe we should focus rather on creating
a repository directory and help users discover plugins, but put up a 'there
be dragons' sign when they are leaving our small, curated collection of
plugins.
Look forward to chatting about it next week...
Regards
Tim
On Wed, Sep 30, 2026 at 4:07 PM Raymond Nijssen via QGIS-Developer <
qgis-developer at lists.osgeo.org> wrote:
> Hi, I also agree the plugin policies need to be changed. Also check the
> email from Stefano earlier today. I'm really feeling sorry for the ones
> who are dealing with all the new plugins.
>
> Just some ideas from my side:
>
> More plugin metadata:
> * description where to find the plugin in QGIS
> * plugin language(s)
> * code is generated by AI
> * plugin needs a (paid) account to function
> * plugin has software dependencies
> * a category?
>
> Detect some IMHO real bad quality signs:
> * Icon is still the default plugin builder icon (or even missing)
> * Dialogs are not responsive
>
> Some quality constraints for uploading to the plugin repository could be:
> * Plugin should use as much as possible the QGIS functionality. For
> example, the plugin should not read or write a shapefile from disk, but
> work on vector layers. QGIS can read and write the shapefile (an many
> more).
> * Plugin must be in English, translations can be done by Qt tr() function.
> * If possible, data manipulations must be through processing algorithms
> * All web traffic must be using QgsNetworkAccessManager (to make
> debugging possible)
>
> We could also consider having a paid repo, with paid staff keeping it
> clean, high quality and safe. We could also make it easier to add/find
> other, less strictly maintained, repos.
>
> Love to discuss this next week in Laax!
>
> Raymond
>
>
>
> On 9/30/26 13:59, Régis Haubourg via QGIS-Developer wrote:
> > Hi, I agree that our community repository is really large now and the
> > world has changed. What should be the direction we should take according
> > to you? Something like an official repo, with a real security triage,
> > and a filter of really up to date and active tools?
> > And besides this, community repositories, not activated by default ?
> > Thanks for your ideas, user conference and community meeting is next
> > week and a dedicated session would be wonderful
> > Cheers
> > Régis
> >
> >
> > On 30/09/2026 13:31, Nicolas Godet via QGIS-Developer <qgis-
> > developer at lists.osgeo.org> wrote:
> >> Dear all,
> >>
> >> I can’t agree more on the fact that the plugin repo has become a wild
> >> jungle with less and less interest in digging into it to find an
> >> innovative one.
> >> A few years ago, I spent a few minutes each week looking at each new
> >> plugin (because there were only ten or so). Now, I don’t look at new
> >> plugins anymore because there are too many of them and most of them
> >> are a duplicate of another plugin or, even worse, of a core feature.
> >>
> >> I think new rules should be put in place or at least a way to
> >> distinguish good, community-approved plugins from the nonsense garbage
> >> in the quest for likes for their LinkedIn post.
> >>
> >> Kind regards,
> >> Nicolas
> >>
> >> > Le 29 sept. 2026 à 17:45, Stefano Campus via QGIS-Developer <qgis- >
> >> developer at lists.osgeo.org> a écrit :
> >> >
> >> >
> >> > Good morning,
> >> > a few days ago, a plugin [1] was released that is a fork of an >
> >> existing plugin which had been updated (without the original plugin >
> >> author being notified) to QGIS 4.
> >> > The GitHub repository has issues disabled, so it is not possible to
> >> > report bugs that are present.
> >> >
> >> > But shouldn’t it be mandatory to have issue reporting enabled?
> >> >
> >> > Furthermore, the proliferation of plugins makes it difficult to find
> >> > the truly innovative ones.
> >> > So we see plugins that replicate core functions, perhaps giving them
> >> a > more appealing user interface
> >> >
> >> > Where can I report this to the team that coordinates the plugins?
> >> > Do you think we should report these anomalies?
> >> >
> >> > Many thanks
> >> >
> >> > stefano
> >> >
> >> > [1] https://github.com/veogeo/go3streetview <https://github.com/ >
> >> veogeo/go3streetview>
> >> > _______________________________________________
> >> > QGIS-Developer mailing list
> >> > QGIS-Developer at lists.osgeo.org
> >> > List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
> >> > Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
> >>
> >> _______________________________________________
> >> QGIS-Developer mailing list
> >> QGIS-Developer at lists.osgeo.org
> >> List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
> >> Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
> >>
> > _______________________________________________
> > QGIS-Developer mailing list
> > QGIS-Developer at lists.osgeo.org
> > List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
> > Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
>
> _______________________________________________
> QGIS-Developer mailing list
> QGIS-Developer at lists.osgeo.org
> List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
> Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
>
--
Tim Sutton
*Kartoza Cofounder*Tim is a member of the QGIS Project Steering Committee
*E *: tim at kartoza.com *W* : kartoza.com
*This email and any attachments are confidential and intended solely for
the use of the individual or entity to whom they are addressed. If you *
*have received this email in error, please notify the sender immediately
and delete it from your system. Unauthorised use, disclosure, or copying*
*of the contents is prohibited.*
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.osgeo.org/pipermail/qgis-developer/attachments/20260930/c6372ecb/attachment.htm>
More information about the QGIS-Developer
mailing list