Enterprise Should Automatically Enable Secret Scanning Across All Organizations/Repositories
policy name: enable_secret_scanning_for_new_orgs
severity: MEDIUM
Description
Enable GitHub Advanced Security secret scanning to alert on sensitive data that exists in your enterprise. Secrets shouldn’t be hard-coded in to your repositories as they will be retrievable by anyone with access to the repository.
Remediation
- Make sure you are an enterprise owner
- Go to the Enterprise Settings page
- Under the ‘Settings’ tab choose ‘Code security and analysis’
- Check ‘Automatically enable for new repositories with Advanced Security enabled’