Omahub
← All plugins
J

Swiss Weather

by Jerome Maeder

Swiss weather from MeteoSwiss: station measurements, forecasts with their 10-90 % uncertainty bands, and day/week/wind charts. Favourite towns searchable offline, warnings with optional notifications, in English, French or German.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
aea6cb7
Scanned
2 weeks ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts docs/security.md:25

    Network download combined with a script interpreter.

    curl` — there is no `sh -c`, so there is no quoting to get wrong. Requests

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
aea6cb7
Reviewed
2 weeks ago

The plugin is a well-engineered weather widget that fetches data from MeteoSwiss and ipapi.co using strict host allowlisting, argv-based curl invocations (no shell), bounded requests, and input validation. The deterministic finding is in documentation only and does not reflect the actual code. No dangerous behavior, obfuscation, or persistence was found.

  • The plugin makes a one-time geolocation request to ipapi.co if detectLocation is enabled, which is opt-in and documented.
  • It launches omarchy-notification-send and xdg-open, but only with validated, literal arguments.
  • The deterministic scan flagged a curl reference in docs/security.md, but that is documentation, not executable code.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/jmaeder/omarchy-swissweather --enable
Widgets #bar #quickshell #system

Swiss Weather

MeteoSwiss weather in the Omarchy bar: what the nearest station measured ten minutes ago, the forecast with its uncertainty, and the warnings in force — in English, French or German.

Left alone it is one weather symbol in the bar. Click it and it becomes a full panel.

The Swiss Weather panel opening from the Omarchy bar

Highlights

  • Measured, not only forecast. Temperature, precipitation, wind and sunshine as an SMN station actually recorded them, stamped with the station and the minute, next to the 10–90 % forecast band for the same hour.
  • Warnings in force, in MeteoSwiss's own two categories — Bad weather and Natural hazards — each named with its danger level and published colour, and each category switchable on its own.
  • Notifications for new warnings of danger level 3 and above, off until you ask for them.
  • Three charts: today by the hour, the week ahead, and 48 hours of wind with its gusts, all with their uncertainty bands.
  • Every Swiss postal code, 4071 of them, searchable by name or number — offline, because the index ships with the plugin.
  • English, French or German, metric or imperial. Unit conversion is arithmetic done on your machine.
  • One notification for every favourite — a drop-in replacement for Omarchy's SUPER + CTRL + ALT + W.
Today The week
Hourly temperature, precipitation and sunshine for today Six days with symbol, high, low and expected precipitation

Install

omarchy plugin add https://github.com/jmaeder/omarchy-swissweather.git --enable

--enable asks where to put it in the bar. To place it yourself:

omarchy plugin enable jmaeder.swissweather center --before omarchy.clock

Needs Omarchy 4 (Quattro) with shell plugin support, curl, and a Nerd Font for the weather symbols — a stock install has all three.

Replacing the built-in weather widget

Omarchy ships its own omarchy.weather. The two run happily side by side — that is what the small Swiss cross on this one's symbol is for — but one is usually enough:

omarchy plugin disable omarchy.weather

One key binding goes with it. SUPER + CTRL + ALT + W calls the built-in widget; point it here instead, in ~/.config/hypr/bindings.lua:

hl.unbind("SUPER + CTRL + ALT + W")
o.bind("SUPER + CTRL + ALT + W", "Weather", "omarchy-shell jmaeder.swissweather summary")

Same key, same habit: one notification with every favourite's current weather.

Swiss Weather · 18:00
Bern (BE)        15.7 °C · 0.0 mm · 4 km/h · 0 min
Davos Dorf (GR)  13.7 °C · 0.0 mm · 5 km/h · 0 min
Engelberg (OW)   19.8 °C · 0.4 mm · 5 km/h · 0 min

Controls

Action Result
Left click the bar item Open / close the panel
Middle click Refresh now
Right click Next favourite town
Click any value Open its chart
Enter Town search
1…9 Jump to that favourite — or, in the charts, Today / Week
Esc Back, then close
h The keyboard shortcuts, over the panel

Settings

In ~/.config/omarchy/shell.json, on the plugin's entry:

Key Default Meaning
showTemperature false Show the temperature next to the bar symbol
swissCross true Badge the bar icon with a small Swiss cross
refreshMinutes 15 Poll interval, clamped to 5–180 minutes
language (locale) en, fr or de; the panel's own selector overrides it
detectLocation true Detect your region once, on first run

Data and privacy

Everything on screen is MeteoSwiss data, from data.geo.admin.ch and the service behind the official MeteoSwiss app. Location detection is one request to ipapi.co, at most once, and only if you leave detectLocation on. Those three hosts are the only ones the plugin ever contacts; the list is enforced in code and redirects are not followed. Town search runs against the bundled index, so what you type is never part of a request. The plugin writes one file: its own state under ~/.local/state/omarchy/plugins/jmaeder.swissweather/.

MeteoSwiss Open Data may be used freely provided the source is cited, which the panel does in its footer. The MeteoSwiss weather graphics are proprietary and are not used: the plugin takes the documented symbol numbers and draws its own Nerd Font glyphs.

Documentation

  • Manual — the panel in detail, notifications, IPC, where it starts, removing it
  • Where the data comes from — every source, and why the maps and weather cams are links
  • Privacy and security — what it fetches, launches and writes, and what it refuses
  • Development — layout, tests, iterating on a live shell

Licence

MIT — see LICENSE.

Weather data: Source: MeteoSwiss, used under the MeteoSwiss Open Data terms of use. This plugin is not affiliated with or endorsed by MeteoSwiss.