Omahub
← All plugins
S

Pacman Sentry

by SVIGHNESH

Pending pacman update count in the bar; popup flags risky packages, shows Arch news, and lists .pacnew files.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
90cdd91
Scanned
1 month ago
  • medium package_manager manifest.json:7

    System package manager operation.

    pacman update count in the bar; popup flags risky packages, shows Arch news, and lists .pacnew files.",

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
90cdd91
Reviewed
1 month ago

The plugin is a benign Arch Linux update monitor: it runs checkupdates, fetches Arch news, and scans /etc for .pacnew files, all read-only operations. The only system-modifying action is launching the user's own update command when the user presses 'u' in the overlay, which is clearly user-initiated. The deterministic 'medium' finding is based solely on the manifest description mentioning pacman, which is expected for this tool and not a real risk.

  • Runs checkupdates and curl on a timer, but these are read-only and standard for a pacman status widget.
  • Scans /etc with find for .pacnew/.pacsave files; read-only and non-destructive.
  • The 'u' key launches omarchy-update in a terminal, but only on explicit user action.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/SVIGHNESH/pacman-sentry --enable
System #bar #system

Pacman Sentry

Keep an eye on pacman without leaving your bar. Every Omarchy user is an Arch user - Pacman Sentry makes sure a linux or nvidia bump, a "manual intervention required" news post, or a forgotten .pacnew never sneaks past you.

Features

  • Bar widget: pending update count from checkupdates (refreshed every 30 minutes, no root needed). The icon turns urgent when a risky package is in the batch or unread Arch news is waiting.
  • Overlay popup (click the widget or bind a key):
    • Latest Arch news with manual intervention posts flagged; click a post to open it.
    • Pending updates with risky packages (kernels, nvidia, systemd, grub, mkinitcpio, glibc, mesa, ...) sorted first and flagged.
    • Unmerged .pacnew / .pacsave files under /etc.
  • Opening the overlay marks news as read; the bar calms down.

Install

omarchy plugin add https://github.com/SVIGHNESH/pacman-sentry
omarchy plugin enable svighnesh.pacman-sentry
omarchy bar move svighnesh.pacman-sentry   # place the widget if needed

Requires pacman-contrib (for checkupdates), curl, and python3 - all standard on Omarchy.

Keybinding (optional)

Add to ~/.config/hypr/bindings.lua:

o.bind("SUPER + ALT + P", "Pacman Sentry", "omarchy-shell shell summon svighnesh.pacman-sentry '{}'")

Keys in the overlay

Key Action
↑ / ↓, j / k Scroll
r Re-check now
u Launch the system update in a terminal
Esc / q Close

Uninstall

omarchy plugin remove svighnesh.pacman-sentry

Cache lives in ~/.cache/pacman-sentry/ and can be deleted freely.

License

MIT