diff --git a/README.md b/README.md index 7a94de3..5824767 100644 --- a/README.md +++ b/README.md @@ -207,6 +207,10 @@ Removing a repository from the YAML archives it instead of deleting it. Every re Every repository is managed with `delete_branch_on_merge = true`, so GitHub deletes a pull request's head branch once it is merged. A deleted branch can be restored from its pull request. +### Secret Scanning + +Every repository is managed with secret scanning and push protection enabled, so GitHub alerts on committed secrets and blocks pushes containing them. Non-provider patterns and validity checks are not managed. + Set it as source of truth: ```shell diff --git a/terraform/modules/repository/main.tf b/terraform/modules/repository/main.tf index 773ee38..7d7224b 100644 --- a/terraform/modules/repository/main.tf +++ b/terraform/modules/repository/main.tf @@ -11,6 +11,16 @@ resource "github_repository" "this" { delete_branch_on_merge = true is_template = var.repository.is_template + # advanced_security omitted: setting it errors on public repositories. + security_and_analysis { + secret_scanning { + status = "enabled" + } + secret_scanning_push_protection { + status = "enabled" + } + } + # Contents dynamic "template" { for_each = var.repository.template == null ? [] : [var.repository.template] diff --git a/terraform/modules/repository/tests/repository.tftest.hcl b/terraform/modules/repository/tests/repository.tftest.hcl index e949bb9..78d3912 100644 --- a/terraform/modules/repository/tests/repository.tftest.hcl +++ b/terraform/modules/repository/tests/repository.tftest.hcl @@ -33,6 +33,16 @@ run "name_only" { condition = github_repository.this.delete_branch_on_merge error_message = "Repository must delete branches on merge." } + + assert { + condition = github_repository.this.security_and_analysis[0].secret_scanning[0].status == "enabled" + error_message = "Repository must enable secret scanning." + } + + assert { + condition = github_repository.this.security_and_analysis[0].secret_scanning_push_protection[0].status == "enabled" + error_message = "Repository must enable secret scanning push protection." + } } run "name_leading_dot" {