Projects holding source code, secrets, or business data should set visibility = private. Public visibility exposes the source tree, issues, merge requests, and snippets to anonymous internet users. Use the GL_Project_Visibility_Should_Not_Be_Public rule for the less-strict variant that also accepts internal.
1. Go to project Settings > General > Visibility, project features, permissions. 2. Set Project visibility to Private. 3. Save changes.
{
"target": "GLProject",
"if": {
"allOf": [
{
"resource": "GLProject",
"property": "Visibility",
"operator": "equals",
"value": "private"
}
]
},
"then": {
"effect": "Audit"
}
}
Copyright © DevOps Shield. Tous droits réservés. Politique de confidentialité | Politique de témoins | Conditions d'utilisation | v1.0.2