Restrict SCM Repository Creation¶
Ensure source control management (SCM) systems enforce strict permissions for repository creation. Limiting this ability to authorized users or teams helps maintain governance, avoid shadow repositories, and reduce security risks.
Mitigation Steps¶
-
Enable repository creation restrictions in the SCM platform (e.g., GitHub, GitLab, Bitbucket). For example, in GitHub Enterprise:
- Navigate to Organization Settings > Member Privileges.
- Disable "Allow members to create repositories."
- Assign repository creation privileges to specific roles.
-
Use role-based access controls (RBAC) to assign repository creation permissions.
- Audit and monitor newly created repositories regularly.
- Implement approval workflows for repository creation, if supported by the SCM tool.