Omahub
← All plugins
F

RSS Headlines

by Flavio Medeiros

RSS headlines in the Menu Bar, powered by Newsboat.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
166bd57
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
166bd57
Reviewed
1 month ago

The plugin is a well-structured RSS reader that delegates fetching to Newsboat and shows articles in a bar panel. It includes defensive coding (input validation, symlink/FIFO protection, bounded output) and no obvious malicious behavior. The main risk is that it executes a user-provided feed URL via xdg-open)Skip, but that is expected functionality and requires user interaction.

  • Opening article URLs via xdg-open could launch arbitrary protocols if a feed contains a malicious URL, but the plugin validates HTTP(S) for configured feeds and only opens cached URLs on user click.
  • The backend writes to user-writable state files and uses O_NOFOLLOW to mitigate symlink attacks; no significant risk found.
  • The plugin installs Newsboat via a package manager command, which is a standard user-initiated action and not a hidden destructive operation.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/flaviomedeiros/rssheadlines --enable
Widgets #bar #quickshell

RSS Headlines

RSS Headlines is an independent community plugin for the Omarchy Menu Bar. The panel presents a configurable number of recent articles collected from a configurable number of feeds, while Newsboat provides feed retrieval, caching, read status, and terminal access.

Features

  • News icon and article panel integrated with the Menu Bar.
  • Feed selector using the titles displayed by Newsboat.
  • First-run feed discovery from the plugin state and standard Newsboat locations.
  • Omarchy Releases as the starter feed for a fresh configuration.
  • Built-in settings for the article limit, feed limit, feed URLs, and refresh interval.
  • Browser opening with synchronized Newsboat read status.
  • Desktop notifications through the active Omarchy theme.
  • Feed refresh pauses with Omarchy's global notification silencing and resumes when notifications are enabled.
  • Relative last-refresh time in the article panel.
  • Manual refresh with right-click, the panel action, or R.
  • Terminal access with middle-click, the panel action, or T.
  • Keyboard navigation with arrow keys, Enter, Esc, F for feeds, and S for settings.

Requirements

  • Omarchy 4.0 or later.
  • Python 3, included with Omarchy.
  • Newsboat, available through the guided setup in the panel.

Installation

Install and enable the plugin from its Git repository:

omarchy plugin add https://github.com/flaviomedeiros/rssheadlines --enable

The first activation performs the complete setup:

  1. Reads subscriptions from ~/.local/share/rss-headlines/urls, ~/.config/newsboat/urls, and ~/.newsboat/urls.
  2. Imports HTTP(S) feeds in that order, up to the configured feed limit.
  3. Uses https://github.com/basecamp/omarchy/releases.atom under the title Omarchy Releases when feed discovery returns an empty list.
  4. Persists the selected URLs in the Omarchy Menu Bar configuration.
  5. Creates the dedicated Newsboat URLs and configuration files.
  6. Starts the first feed refresh.

When Newsboat setup is required, the panel presents an Install Newsboat action and the I shortcut. The action opens a terminal running:

omarchy pkg add newsboat

Reopen the panel after the package command completes to load the articles.

Configuration

Click the RSS Headlines icon in the Menu Bar, then click the gear button in the panel header. The built-in settings screen provides:

  • Articles to display: maximum number of recent articles shown in the panel.
  • Maximum feeds: maximum number of feed URLs used by the plugin.
  • Feed URLs: http:// or https:// addresses separated by spaces, commas, semicolons, or line breaks.
  • Refresh interval: time between automatic checks, in seconds.

Select Save to apply the settings and refresh the articles. Cancel, the back button, or Esc returns to the article list without applying the draft. Ctrl+Enter saves while the feed URL field is active, and S opens the settings from the article list.

The same settings remain available under Omarchy → Style → Menu Bar → RSS Headlines. The initial Omarchy Releases subscription is editable from either location.

The Feed selector at the top of the article list starts with All feeds and then lists each configured feed under the title displayed by Newsboat. Selecting a feed reads its articles from the local cache without downloading the subscriptions again. Press F to open the selector from the keyboard.

Example:

https://example.com/feed.xml; https://example.org/atom.xml

Newsboat state and terminal access

The plugin keeps its Newsboat state in:

~/.local/share/rss-headlines/urls
~/.local/share/rss-headlines/cache.db
~/.local/share/rss-headlines/config

The panel opens Newsboat with these files. The equivalent terminal command is:

newsboat \
  -u ~/.local/share/rss-headlines/urls \
  -c ~/.local/share/rss-headlines/cache.db \
  -C ~/.local/share/rss-headlines/config

Standard Newsboat URL files participate in first-run discovery, while the plugin runtime uses its dedicated state directory.

Read status and notifications

Opening an article launches its cached HTTP(S) URL through xdg-open. A successful launch marks the exact cache entry as read and updates the Menu Bar counter.

Each feed refresh uses Newsboat's notify-program integration. A refresh that discovers new articles calls the notification adapter, which sends a themed desktop notification through omarchy notification send.

RSS Headlines follows Omarchy's global Silence Notifications mode, so it does not add a separate notification toggle. While notifications are silenced, scheduled and manual feed refreshes are deferred and the cached article list remains available. When notifications are enabled again, the plugin refreshes immediately; Newsboat then reports the articles accumulated since the previous refresh. If a refresh was already finishing when silence began, the notification adapter preserves its message and delivers it after silence ends.

Removal

Remove RSS Headlines with:

omarchy plugin remove com.flaviomedeiros.rss.headlines

This removes the plugin while keeping Newsboat available for terminal use. If you no longer use Newsboat, remove it separately with:

omarchy pkg drop newsboat

Development and validation

omarchy plugin validate .
python3 -m unittest discover -s tests -v
./tests/smoke_qml.sh
./tests/test_notify.sh

Run the live integration test against the Omarchy releases feed with:

RUN_NEWSBOAT_INTEGRATION=1 python3 -m unittest tests.test_integration -v

The backend delegates feed retrieval and parsing to Newsboat, then queries Newsboat's rss_feed and rss_item tables for the panel model.

License

MIT.