Skip to content

Security: mirashif/omarest

Security

SECURITY.md

Security and privacy

OmaRest is unsandboxed QML running inside the long-lived Omarchy shell, as all Omarchy shell plugins are. Install it only from a repository and revision you trust.

The plugin reads the active Wayland application ID, invokes hyprctl -j activewindow as a bounded fallback health check, reads Omarchy's in-process idle/lock state, and writes its two XDG JSON files. It does not use the network.

Report a vulnerability privately through GitHub's Security → Report a vulnerability flow for the repository. Do not open a public issue for a bug that could expose user activity or compromise the shell process.

There aren't any published security advisories