Omahub
← All plugins
E

Official Arch

by Elliot

Install selected Arch packages from the live official Extra/Core mirrors, bypassing Omarchy's delayed snapshot.

Security review

Review recommended · 7 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
f225cf5
Scanned
1 month ago
  • Command runs with sudo, elevating the process beyond the plugin environment.

    SUDO pacman -U https://geo.mirror.pkgbuild.com/extra/os/x86_64/ollama-0.32.14-1-x86_64.pkg.tar.zst' \
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -U with the official URL"
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo is required" >&2; exit 1; }
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -U "${URLS[@]}"
  • Docs sudo README.md:5

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -U` against `https://geo.mirror.pkgbuild.com`. Other packages stay on Omarchy's mirror.
  • Docs sudo README.md:11

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo password
  • Docs sudo README.md:34

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -U`.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
f225cf5
Reviewed
1 month ago

The plugin does what it advertises: it lets the user install package names they type from Arch's official mirror using sudo pacman -U, after validating package names and filenames and fetching metadata from archlinux.org. No obfuscation, persistence, credential theft, or hidden destructive behavior was found; the sudo findings are expected for the plugin's stated purpose and require explicit user action.

  • The helper runs sudo pacman -U with URLs from the official Arch mirror, so installing a package is an intentional root-level system change.
  • Trust depends on the integrity of archlinux.org and geo.mirror.pkgbuild.com, which is the standard Arch trust model.
  • The widget can install packages newer than the Omarchy snapshot, which may cause package-version skew until the snapshot catches up.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/cempack/omarchy-arch-extra --enable
System #bar #quickshell #system

Official Arch

Install selected Arch packages from the live official mirrors, bypassing Omarchy's delayed snapshot for those packages only.

Omarchy's omarchy pkg add and menu installer use the configured channel mirror. This plugin looks up archlinux.org package metadata and runs sudo pacman -U against https://geo.mirror.pkgbuild.com. Other packages stay on Omarchy's mirror.

Requirements

  • Omarchy 4 / Quattro shell
  • curl, jq, sudo, uwsm-app, and xdg-terminal-exec
  • A terminal that can prompt for your sudo password

The plugin does not write sudoers rules, does not use pkexec, and does not pipe downloads into a shell. Package names are validated before any network call. The helper only accepts core, extra, or multilib and only downloads *.pkg.tar.zst|xz|gz filenames from the official geo mirror.

Install

omarchy plugin add https://github.com/cempack/omarchy-arch-extra.git --enable

For a local checkout:

PLUGIN_ID="io.github.cempack.arch-extra"
PLUGIN_DIR="$HOME/.config/omarchy/plugins/$PLUGIN_ID"
rsync -a --delete --exclude .git --exclude test "$PWD/" "$PLUGIN_DIR/"
omarchy plugin validate "$PLUGIN_DIR"
omarchy-shell shell rescanPlugins
omarchy plugin enable "$PLUGIN_ID" --section right

Usage

Click the package icon in the bar. Type one or more official package names, then press Enter or Install. A floating terminal lists the resolved URLs and runs sudo pacman -U.

omarchy-shell shell summon io.github.cempack.arch-extra '{}'
omarchy-shell shell hide io.github.cempack.arch-extra

Until Omarchy's snapshot catches up, later official Arch releases of those packages need another install from this panel. Avoid pacman -Syu/-Suu if you need to keep a newer package than the Omarchy mirror.

Configure

omarchy bar move io.github.cempack.arch-extra --section right

Widget settings repo (extra, core, or multilib) and arch (x86_64 or aarch64) live on the plugin's bar entry in ~/.config/omarchy/shell.json.

Tests

node test/model-test.js
bash test/install-from-arch-test.sh
node test/qml-contract-test.js
omarchy plugin validate "$PWD"

Remove

omarchy plugin remove io.github.cempack.arch-extra

License

MIT. See LICENSE.