Table of contents
- API Request Rate Limit Should Be Limited
- Branch Protection Should Be Globally Enabled By Default
- Creating Public Repositories Should Be Restricted To Admins
- Default Group Visibility Should Not Be Public
- Default Project Visibility Should Not Be Public
- Password Authentication For Git Over HTTP(S) Should Not Be Enabled
- Server Should Not Allow Access To Unauthenticated Users With Sign-Up
- Sign-Up Confirmation Email Should Be Mandatory
- Two-factor Authentication Should Be Globally Enforced
- Unauthenticated Requests Rate Limit Should Be Enabled
- Webhooks Should Not Be Allowed To Be Sent To The Local Network