1.2.3 Ensure repository deletion is limited to specific users
ID |
cis_sscs/repository_deletion |
Severity |
high |
Category |
source_code/repository |
Levels |
|
Optional |
false |
Tags |
least-privilege, repo-permissions, slsa-3, slsa-4 |
Rationale
Restricting the ability to delete repositories protects the organization from intentional and unintentional data loss. This ensures that users cannot delete repositories or cause other potential damage — whether by accident or due to their account being hacked — unless they have the correct privileges.