Presented Thursday, September 24, 2026, at JNUC 2026, Kansas City, MO.

Download the slides (PDF)

Description

I once committed an API key to a repository and did not catch it myself. Security found it three days later. That mistake made me rethink the way I was moving scripts from my editor into Jamf Pro.

In this session I follow one deliberately bad script through two gates. Betterleaks and ShellCheck block the secret and shell bugs locally before the commit is created. GitHub Actions runs the same checks again on the pull request, so bypassing a local hook does not bypass the review process.

I also show how Shikomi builds that workflow into a new project: version headers, a README and changelog, pre-commit checks, pull request validation, and optional deployment to Jamf Pro. The practical starting point is one new script, not a migration of every script you already have.