{"name": "Quick Dutch Basemap", "package_name": "quick_dutch_basemap", "version": "1.2", "experimental": false, "qgis_min": "3.16.0", "qgis_max": "3.99.0", "downloads": 242, "uploaded_by": "moinul95", "upload_datetime": "2026-09-06T22:15:24.202182", "changelog": "1.2\n- Removed the vendored defusedxml dependency (it caused a ModuleNotFoundError on load, and its own bundled files were also being flagged by the security scanner).\n- XML parsing is now done with a small, self-contained hardened parser built on the standard library's expat module, with DOCTYPE declarations, custom entities, and external entity resolution all explicitly disabled.\n- Added a security-scanner suppression comment on the capabilities download call, since the URL is always a hardcoded HTTPS constant.\n1.1\n- Fixed security scan findings: switched XML parsing from xml.etree.ElementTree to defusedxml, and added an explicit HTTPS-only scheme check before fetching capabilities.\n- Layer list now loads instantly from a popup menu (click a layer name to load it immediately, no OK button).\n- Layer list is fetched once in the background when the plugin loads, instead of on every click.\n- Layers are grouped by resolution (8cm first, then 25cm), with menu styling and shortened labels for easier scanning.\n1.0\n- Initial release.", "external_deps": null, "download_url": "https://plugins.qgis.org/plugins/quick_dutch_basemap/version/1.2/download/"}