1.2 - Removed the vendored defusedxml dependency (it caused a ModuleNotFoundError on load, and its own bundled files were also being flagged by the security scanner). - XML parsing is now done with a small, self-contained hardened parser built on the standard library's expat module, with DOCTYPE declarations, custom entities, and external entity resolution all explicitly disabled. - Added a security-scanner suppression comment on the capabilities download call, since the URL is always a hardcoded HTTPS constant. 1.1 - Fixed security scan findings: switched XML parsing from xml.etree.ElementTree to defusedxml, and added an explicit HTTPS-only scheme check before fetching capabilities. - Layer list now loads instantly from a popup menu (click a layer name to load it immediately, no OK button). - Layer list is fetched once in the background when the plugin loads, instead of on every click. - Layers are grouped by resolution (8cm first, then 25cm), with menu styling and shortened labels for easier scanning. 1.0 - Initial release.
yes
moinul95
2026-09-07T03:15:24.202182+00:00
3.16.0
3.99.0
None
no
Plugin Tags