Omahub
← All plugins
G

Omaweather

by Gedankenn

Current weather in the Omarchy bar, with a city search and a native temperature graph on click.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
8d7eaa6
Scanned
1 week ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs sudo README.md:20

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo or pkexec is required.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
8d7eaa6
Reviewed
1 week ago

This is a benign weather bar widget that fetches data from Open-Meteo and wttr.in over HTTPS using curl with size caps. The deterministic scan's 'sudo' finding is a false positive—the README explicitly states no sudo is required and the snippet is documentation only; no code elevates privileges. No obfuscation, persistence, credential theft, or destructive commands were found.

  • The plugin reads ~/.local/state/omarchy/settings/weather.json and writes plugin settings, which is normal for Omarchy widgets.
  • Network requests to external APIs are expected and size-limited; no data exfiltration or unexpected endpoints observed.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Gedankenn/omaweather --enable
Widgets #bar

Omaweather

<p align="center"> <strong><a href="https://open-meteo.com">Open-Meteo</a> weather, living in your Omarchy bar.</strong><br> Emoji and temperature up top. A native three-day graph on click, with a dashed amber line and a dot that mark the current hour right on the curve. </p> <p align="center"> <img src="preview.png" width="480" alt="Omaweather in the Omarchy bar: emoji and temperature on the chip, and a colored three-day temperature graph with rain bars and condition icons in the popup"> </p> <p align="center"> <a href="https://omarchy.org"><img src="https://img.shields.io/badge/Omarchy-Quattro-111111?style=flat-square" alt="Omarchy Quattro"></a> <a href="LICENSE"><img src="https://img.shields.io/badge/license-MIT-e6c35c?style=flat-square" alt="MIT license"></a> <a href="https://open-meteo.com"><img src="https://img.shields.io/badge/data-open--meteo-87ff00?style=flat-square" alt="Open-Meteo"></a> </p>

A real vector graph drawn inside the shell — a temperature curve colored from cold blue to hot red, rain bars, condition icons, and the day's sunrise and sunset — in your bar font and theme colors.

No sudo or pkexec is required.

Install

omarchy plugin add https://github.com/Gedankenn/omaweather.git --enable

It lands in the center of the bar, next to the clock. Move it anywhere:

omarchy bar move io.github.gedankenn.omaweather --section right

What you get

In the bar In the popup
Weather emoji + temperature Current conditions, feels-like, wind, humidity
Tooltip with wind and humidity Three-day temperature curve with a cold-to-hot gradient
Refreshes every 15 minutes Rain bars, condition icons, sunrise and sunset

Usage

Input Action
Left click Open or close the forecast
Click the city name Search and pick a city
Enter Same city search, while the panel is open
Empty search Back to the default location
Middle click Refresh now
Right click Desktop notification with current conditions
r Refresh while the panel is open
Escape Close the search, or the panel

Configure

The simple way: open the popup, click the city name, type, pick a result. That stores the name plus coordinates so the next fetch hits the right place.

Settings also live on the widget entry — the Omarchy config UI, or:

omarchy bar set io.github.gedankenn.omaweather location "Pato Branco"
omarchy bar set io.github.gedankenn.omaweather refreshMinutes 20
Key Default Meaning
location empty City name or lat,lon. Empty falls back to the Omarchy weather.json location, then to Pato Branco.
refreshMinutes 15 How often to refetch. Minimum 1.

The plugin does not overwrite user configuration. Removing it only drops its bar entry.

Data

Everything — the bar chip, the current-conditions summary, and the three-day graph — comes from Open-Meteo over HTTPS, the same keyless source the Second Coming theme uses. One request returns the current readings, 72 hours of hourly data, and three days of daily highs, lows, rain chance, sunrise, and sunset. It is fetched with curl, and the download size is capped before it reaches the shell (head -c, plus --max-filesize). Remote fields are clipped and treated as plain text. Metric units.

Needs a network connection. If Open-Meteo is slow or down, the last good reading stays on the bar and the plugin retries.

Remove

omarchy plugin remove io.github.gedankenn.omaweather

License

MIT © Fabio Slika Stella