Omahub
← All plugins
J

Pit Wall

by Jeremy Longshore

Pit Wall turns your Omarchy bar into a Formula 1 race-weekend command post. Between sessions it counts down to FP1, qualifying, sprint, or race start; while running it shows the leader, gaps, flags, safety-car state, and live leaderboard. Open the panel for the local-time weekend schedule plus driver/constructor standings. It reads keyless Jolpica schedule/standings data every 15 minutes and OpenF1 every 20 seconds only during sessions. It writes no files outside Quickshell's own state handling.

Security review

Potentially dangerous behavior detected · 11 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
f54d730
Scanned
1 week ago
  • high destructive_filesystem scripts/rig-verify.sh:76

    Destructive operation on the root filesystem or a block device.

    rm -rf /tmp/$NAME && mkdir -p /tmp/$NAME && tar xzf /tmp/$NAME.tgz -C /tmp/$NAME' || exit 3
  • high destructive_filesystem scripts/rig-verify.sh:97

    Destructive operation on the root filesystem or a block device.

    rm -rf /tmp/$NAME /tmp/$NAME.tgz >/dev/null 2>&1
  • medium external_hosts Panel.qml:167

    Downloads or connects to an external HTTP(S) host.

    curl("https://api.openf1.org/v1/position?session_key=latest" + since)
  • medium external_hosts Panel.qml:171

    Downloads or connects to an external HTTP(S) host.

    curl("https://api.openf1.org/v1/intervals?session_key=latest" + since)
  • medium external_hosts Panel.qml:177

    Downloads or connects to an external HTTP(S) host.

    curl("https://api.openf1.org/v1/race_control?session_key=latest")
  • medium external_hosts Panel.qml:205

    Downloads or connects to an external HTTP(S) host.

    curl("https://api.jolpi.ca/ergast/f1/current.json?limit=30")
  • medium external_hosts Panel.qml:222

    Downloads or connects to an external HTTP(S) host.

    curl("https://api.jolpi.ca/ergast/f1/current/driverstandings.json")
  • medium external_hosts Panel.qml:234

    Downloads or connects to an external HTTP(S) host.

    curl("https://api.jolpi.ca/ergast/f1/current/constructorstandings.json")
  • medium external_hosts Panel.qml:246

    Downloads or connects to an external HTTP(S) host.

    curl("https://api.openf1.org/v1/drivers?session_key=latest")
  • medium external_hosts Panel.qml:262

    Downloads or connects to an external HTTP(S) host.

    curl("https://api.openf1.org/v1/sessions?session_key=latest")
  • Augments a command with octal/hex escape sequences.

    \x89PNG\r\n\x1a\n" or raw[12:16] != b"IHDR":

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
f54d730
Reviewed
1 week ago

Pit Wall is a read-only F1 schedule/live-timing bar widget. Its network calls are hardcoded HTTPS requests to the documented public OpenF1 and Jolpica APIs, made via curl argv arrays with byte caps and timeouts, and remote strings are sanitized before rendering. The deterministic high findings come from development/rig scripts that remove scratch directories under /tmp, not from runtime or install code, so they do not pose a real user risk.

  • The deterministic scan flagged rm -rf /tmp/$NAME in scripts/rig-verify.sh, but that script is a developer rig verification tool, not executed on a user's system during install or normal use.
  • The plugin periodically contacts third-party APIs (api.openf1.org, api.jolpi.ca); this is disclosed in the README/manifest and is intrinsic to the widget's purpose. Requests are byte-bounded and carry no credentials.
  • The low-severity obfuscation finding is inside a vendored gate script that inspects PNG banner magic bytes, not in plugin runtime code.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/jeremylongshore/omarchy-pit-wall-entry --enable
Widgets #bar #quickshell #system
<p align="center"><img src="assets/banner.svg" alt="Pit Wall" width="100%"></p>

Pit Wall

The next F1 session, counted down in your Omarchy bar. Live timing from the moment it starts.

A bar pill counts down to the next Formula 1 session, QUALI 2h 14m, then flips to live timing the moment the lights go out. RACE ▸ VER, lit in your theme's active color. Click it for the panel: the full weekend schedule in your local time, the live leaderboard with gaps to the leader, and both championship standings.

Pit Wall preview

ko-fi

Install

omarchy plugin add https://github.com/jeremylongshore/omarchy-pit-wall-entry --enable

Then add Pit Wall to your bar layout (Omarchy menu → Bar, or ~/.config/omarchy/shell.json).

What it shows

  • Between sessions. Pill: next session plus a compact countdown (FP1 2d 4h). Panel: race name, round, circuit, every session of the weekend in local time (past sessions dimmed, the next one bold), plus the top of the drivers' and constructors' championships.
  • During a session. Pill: session plus leader (SPRINT ▸ NOR) in the bar's active color, or the flag when it matters (RACE ▸ SC). Panel: live leaderboard with position, driver, team, and gap to the leader, refreshed every 20 seconds, above the schedule and standings.
  • Middle-click the pill to force a refresh. Esc closes the panel, Tab walks to the neighboring panel, exactly like the built-in widgets.

Where it pulls data: free, keyless, no accounts

Pit Wall makes read-only HTTPS GET requests to two public F1 APIs. No auth, no tokens, no accounts, nothing sent anywhere. These are the only network calls it makes.

jolpica-f1 (api.jolpi.ca), the community successor to the Ergast API, for the schedule and standings:

  • GET api.jolpi.ca/ergast/f1/current.json (weekend schedule)
  • GET api.jolpi.ca/ergast/f1/current/driverstandings.json
  • GET api.jolpi.ca/ergast/f1/current/constructorstandings.json

OpenF1 (api.openf1.org) for the live feed, polled only while a session is running:

  • GET api.openf1.org/v1/sessions (authoritative session window)
  • GET api.openf1.org/v1/drivers
  • GET api.openf1.org/v1/position (leaderboard order)
  • GET api.openf1.org/v1/intervals (gaps to the leader)
  • GET api.openf1.org/v1/race_control (flags, safety car)

Schedule and standings refresh every 15 minutes. Live polling only runs during a session window and fetches incremental tails (the last few minutes of events), so the widget stays light even across a full race distance. Every request is byte-capped so an oversized response can never stall the shell.

Zero configuration

There is no settings form. Pit Wall picks sensible defaults (15-minute schedule refresh, 20-second live polling, 10 leaderboard rows, 5 standings rows) and shows the pill all season. The widget is the configuration.

Theming

No hardcoded colors. Everything reads the bar's palette (foreground, urgent, the panel surfaces) and the shell's typography scale, so Pit Wall looks native in every Omarchy theme.

Remove

omarchy plugin remove io.github.jeremylongshore.pit-wall

Development

The data layer (Model.js) is pure functions shared between the QML runtime and node:

node --test tests/*.test.js

Fixtures under tests/fixtures/ are real captured responses from both APIs.

Maintainers wanted

These plugins are growing, and we are looking for dependable Omarchy users who want to review issues, test releases, and keep a plugin healthy over time. Start with a small pull request or open a maintainer interest issue titled Maintainer interest. Tell us which plugin you use and how you want to help. Consistent contributors can earn maintainer responsibility.

License

MIT. See LICENSE.