Omahub
← All plugins
A

Git

by ariadev

GitHub, GitLab and Gitea open work: a full-year contribution graph, review queue, and your open pull/merge requests in a native Omarchy bar panel.

Security review

Review recommended · 3 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
77bfee2
Scanned
1 month ago
  • medium package_manager …/workflows/ci.yml:13

    System package manager operation.

    apt-get install -y jq shellcheck
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install -y jq shellcheck
  • Docs external_hosts README.md:29

    Downloads or connects to an external HTTP(S) host.

    curl` and `jq`, plus any of [gh](https://cli.github.com/),

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
77bfee2
Reviewed
1 month ago

The plugin is a straightforward Git dashboard: a bash collector reads credentials already held by gh/glab/tea and queries the corresponding Git hosts, then writes a JSON overview for the QML panel. The deterministic scan's medium findings are not runtime risks: the README only documents required tools, and the sudo apt-get command is confined to the GitHub Actions CI workflow. No obfuscation, persistence, credential exfiltration, or destructive behavior was found.

  • The collector reads existing gh/glab/tea credentials and sends them to hosts discovered from those CLIs' config files; this is the intended functionality but means the plugin handles sensitive tokens.
  • Hosts are discovered from user configuration and environment variables, so a compromised or malicious config could direct requests to an unexpected host; the code does not appear to exfiltrate data beyond the configured providers.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ariadev/omarchy-dev-git --enable
Developer Tools #bar #quickshell

dev.git — Git dashboard bar widget for Omarchy

A native Omarchy shell bar widget that watches GitHub, GitLab and Gitea for open work: a full-year contribution graph, review queues, and your own pull and merge requests, all in one panel.

The dev.git panel showing the GitHub and GitLab tabs side by side

Features

  • Full-year activity graph — trailing 53 weeks, quartile-shaded, with per-day tooltips, streaks and today's count
  • Multiple hosts per provider — GitHub Enterprise and self-managed GitLab and Gitea are discovered from gh/glab/tea config, each with its own identity, graph and queues, behind a host switch inside the tab
  • Open-work grid — awaiting review, assigned PRs/MRs, assigned and authored issues; each click opens the pre-filtered queue page
  • Queue rows carrying draft tag, approval check, comment count, repository, number and age
  • A dot on the bar icon when something is waiting on your review
  • Keyboard driven throughout

Install

omarchy plugin add https://github.com/ariadev/omarchy-dev-git.git --enable --yes

Needs curl and jq, plus any of gh, glab and tea signed in — the collector reads the credentials those CLIs already hold and never stores a token of its own. All three are optional: each provider is collected independently, so a missing or unauthenticated one never hides the others.

Nothing is compiled or installed. Clone it and it runs.

Keyboard

Key Action
j / k Move down / up the queue rows
h / l Previous / next provider tab
[ / ] Previous / next host
g / G First / last row
Enter Open the selected row
p Pin the provider tab first
r Refresh now
Tab Neighbouring panel
Esc Close

Left click toggles the panel, middle click cycles providers, right click refreshes.

Open it from a keybinding

The panel exposes an IPC target, so it can be bound to a key. Add to ~/.config/hypr/bindings.lua:

o.bind("SUPER + CTRL + G", "Git dashboard", "omarchy-shell dev.git toggle")

toggle, open, close, refresh and next (cycle provider) are all available — omarchy-shell dev.git refresh refreshes without opening.

How it works

bin/gitwork runs on a timer (default 300 s) and writes one JSON overview to ~/.local/state/omarchy/git/overview.json, which the panel watches. It is a bash script with its JSON transforms in bin/gitwork.jq.

GitHub needs one GraphQL request per host for identity, calendar and all five queues. GitLab takes one GraphQL request for identity and merge requests, REST for issues, and the events feed for the calendar — it has no calendar API — with page one reporting the page count so the rest are fetched together. Gitea has no GraphQL at all, but its issue search takes each queue as query parameters and answers pulls and issues from one row shape, so identity comes first and then the five queues and the heatmap fly together.

Every host is collected in its own subshell, so a run costs the slowest single host rather than the sum of them. A host that cannot be reached carries its last good record forward for up to six hours, marked stale, so a dropped VPN does not blank a working dashboard. An authentication failure is not carried: that data is genuinely gone.

Settings

Key Type Default Description
refreshIntervalSec integer 300 Collector run interval (s)
providers.github.enabled boolean true Show the GitHub tab
providers.gitlab.enabled boolean true Show the GitLab tab

Tests

./tests/run.sh

No network or credentials required — every host the suite touches is deliberately unreachable.

License

MIT