Omahub
← All plugins
W

Vercel

by Wesley Cole

Vercel projects and deployments in the Omarchy bar using your existing CLI login.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
74b43ed
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
74b43ed
Reviewed
1 month ago

The deterministic scan found no issues, and the reviewed code shows no obfuscation, hidden persistence, or destructive behavior. The plugin reads the user's existing Vercel CLI OAuth token and sends it only to api.vercel.com, with documented third-party favicon requests to favicon.im; this is expected functionality for a Vercel widget and is clearly disclosed.

  • The plugin reads the Vercel CLI OAuth token from $XDG_DATA_HOME/com.vercel.cli/auth.json and uses it to authenticate API requests, so it has full access to the user's Vercel account; this is inherent to the plugin's purpose and documented.
  • Project rows send public production hostnames to favicon.im for favicon loading; this is disclosed in the README but is a third-party data exposure.
  • Like all Omarchy shell plugins, it runs unsandboxed with the user's permissions; no privileged operations, install hooks, or persistence mechanisms were observed.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/wesleycole/omarchy-vercel --enable
Developer Tools #bar #quickshell #system

Vercel for Omarchy

A keyboard-driven Omarchy bar widget for Vercel projects, live deployment status, completion notifications, logs, and failed-build alerts. It uses your existing Vercel CLI login and requires no additional credentials.

Install

omarchy plugin add https://github.com/wesleycole/omarchy-vercel.git --enable
omarchy bar move io.github.wesleycole.vercel --section right

Requirements

  • Omarchy with the Quattro shell plugin runtime
  • vercel, authenticated with vercel login
  • curl
  • wl-copy for copy actions

The plugin reads the Vercel CLI OAuth token from $XDG_DATA_HOME/com.vercel.cli/auth.json and the selected team from $XDG_DATA_HOME/com.vercel.cli/config.json. It does not modify either file. Tokens are sent to the Vercel API through curl stdin rather than process arguments or environment variables.

Features

  • Projects with production favicons and live-site shortcuts
  • Account-wide and per-project deployment history
  • Commit message, project, environment, branch, SHA, status, and error details
  • Fast polling while a deployment is active, with a slower idle interval
  • Notifications when an observed deployment becomes ready, fails, or is canceled
  • Persistent acknowledgement of Needs Attention items
  • Vercel dashboard, inspect, build-log, runtime-log, and redeploy actions
  • Keyboard navigation and account-wide search

Keys

Key Action
j / k, arrows Move selection
Enter Drill into a project or open a deployment
p Show all projects
d Show recent deployments
/ Search projects and deployments
o Open live URL
b Open the Vercel project/deployment dashboard
i Inspect a deployment in a visible terminal
l Show deployment build logs in a visible terminal
f Follow deployment runtime logs in a visible terminal
c Copy live URL or ID
R Confirm and redeploy in a visible terminal
r Refresh
C Clear current Needs Attention items
h / Escape Return to the previous view, then close

Mouse controls: left click toggles the panel, right click refreshes, and middle click opens the Vercel dashboard.

Display behavior

Deployment rows use the Git commit message as the title and show the project where needed, status, environment, branch, and short SHA. Project rows load their production-domain favicon through favicon.im, falling back to the original square marker when no production domain is available. This sends each public production hostname to that third-party favicon service when the project list is shown. The panel hero keeps the Vercel triangle in account-level views and switches to the selected project's favicon in its deployment view.

Settings

Add values to the widget entry in ~/.config/omarchy/shell.json:

{
  "id": "io.github.wesleycole.vercel",
  "refreshIntervalSec": 60,
  "activeRefreshIntervalSec": 8,
  "deploymentRows": 20,
  "notifications": true,
  "teamId": ""
}

An empty teamId uses currentTeam from the Vercel CLI config. Set it to personal to show the personal account instead. The plugin polls every activeRefreshIntervalSec seconds while a deployment is queued, initializing, or building, then returns to refreshIntervalSec when idle.

Notifications only fire for deployments first observed running in the current shell session, so startup does not replay historical results. Clearing Needs Attention acknowledges current failed deployment IDs. They remain in deployment history while disappearing from Needs Attention and the bar warning badge. The acknowledgements persist in $XDG_STATE_HOME/omarchy/vercel.json; failures from new deployments still appear normally.

Diagnostics

omarchy-shell io.github.wesleycole.vercel diagnose
quickshell log -p "$OMARCHY_PATH/shell" --tail 100

Security and permissions

Like all Omarchy shell plugins, this plugin runs unsandboxed with your user permissions. It performs no privileged operations and installs no hooks or services. It reads the existing Vercel CLI configuration, makes authenticated requests to Vercel, opens URLs, launches visible terminals for explicit CLI actions, writes acknowledgement state under $XDG_STATE_HOME/omarchy/, and uses favicon.im as documented above. No token value is included in diagnostics or logs.

Remove

omarchy plugin remove io.github.wesleycole.vercel

Optional: remove saved Needs Attention acknowledgements:

rm -f "${XDG_STATE_HOME:-$HOME/.local/state}/omarchy/vercel.json"

Development

omarchy plugin validate .
qmllint -I "$OMARCHY_PATH/shell" Panel.qml Service.qml VercelIcon.qml
omarchy restart shell

JavaScript helpers are cached by the QML engine; restart the shell after editing Api.js or Model.js.