GitHub repository visibility needs review

Check the purpose and contents of public GitHub repositories and keep internal repositories private.

Description

Making a GitHub repository public allows outside readers to access its code and public repository material. Public projects can be intentional; verify the publication purpose and whether the repository contains sensitive information.

Making a repository private does not recall copied code or exposed secrets. Repository visibility, write access and deployment permissions also need separate management.

Potential impact

  • Internal code or operational information may be exposed.
  • Secrets in earlier commits may be copied and misused even after the repository becomes private.

Remediation

Set IsPrivate to true when creating an internal repository and verify its actual GitHub visibility. Change existing repository visibility through a supported GitHub procedure; this CloudFormation property does not support updates. Revoke or replace secrets exposed in history and review collaborator and automation-token permissions.

Examples

These are alternative configurations for creating a new repository. Replace the S3 source, owner, name and token reference with actual values. They do not demonstrate changing an existing repository’s visibility through a template update.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
  MyRepo3:
    Type: AWS::CodeStar::GitHubRepository
    Properties:
      Code:
        S3:
          Bucket: "my-bucket"
          Key: "sourcecode.zip"
          ObjectVersion: "1"
      EnableIssues: true
      IsPrivate: false
      RepositoryAccessToken: '{{resolve:secretsmanager:your-secret-manager-name:SecretString:your-secret-manager-key}}'
      RepositoryDescription: a description
      RepositoryName: my-github-repo
      RepositoryOwner: my-github-account

IsPrivate: false configures a public repository. Confirm that publication is intentional.

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
  MyRepo1:
    Type: AWS::CodeStar::GitHubRepository
    Properties:
      Code:
        S3:
          Bucket: "my-bucket"
          Key: "sourcecode.zip"
          ObjectVersion: "1"
      EnableIssues: true
      IsPrivate: true
      RepositoryAccessToken: '{{resolve:secretsmanager:your-secret-manager-name:SecretString:your-secret-manager-key}}'
      RepositoryDescription: a description
      RepositoryName: my-github-repo
      RepositoryOwner: my-github-account

IsPrivate: true configures a private repository. Being private does not justify embedding secrets in its code.

References