A reusable Bash helper library for macOS administrators — the functions you keep reimplementing in every admin script, done once under one naming convention: core helpers for the system, install and update helpers for popular Mac apps, Jamf extension-attribute helpers and a security audit module.
Twelve core modules: logging, OS and version, users, packages (pkgutil), code signing and notarization, FileVault, keychain, launchd, network, software update, MDM status and profiles, and app install/uninstall.
About 150 modules for Mac apps — Chrome, Firefox, Zoom, Slack, 1Password, Office, Adobe and many more — each with helpers for the installer URL, the latest version and whether the app is installed. Derived from Installomator labels.
Eleven helpers that print their value in the <result> wrapper Jamf extension attributes expect: battery cycle count, security chip, third-party kexts, system extensions, uptime, Xcode CLT state and more.
A CIS-style audit framework with pass/fail/warn reporting and checks for Gatekeeper, the application firewall and SSH, with matching remediation functions.
Namespaced public functions (maclib::<module>::<name>), data on stdout and logs on stderr, no eval, quoted variables, safe under set -euo pipefail.
A Makefile runs shellcheck, shfmt and a bats-core suite. There's no CI workflow in the repository yet, so those checks run locally.
Source the library entrypoint from any Bash script:
source ./lib/maclib.sh
maclib::log::info "Hello from maclib"
About 64 of the ~150 app modules still carry placeholder installer URLs (example.com) until each vendor is researched — treat those as stubs.
A rename of app functions to include their category (e.g. maclib::ai::chatgpt::url) is in progress, so names may change.
Prerequisites: shellcheck, shfmt, bats-core
make lint · make fmt · make test
The modules, how the library is organised, and what is and isn't finished.
📖 Read the documentation