Enterprise Should Automatically Enable Advanced Security Across All Organizations/Repositories
policy name: enable_ghas_for_new_orgs
severity: MEDIUM
Description
Advanced Security includes code scanning, secret scanning and dependency review. These features protect your repositories from containing vulnerable data. Prevents the risk of unauthorized access or exploitation of vulnerabilities.
Remediation
- Make sure you are an enterprise owner
- Go to the Enterprise Settings page
- Under the ‘Settings’ tab choose ‘Code security and analysis’
- Check ‘Automatically enable for new repositories’