Description
Anyone can view the code and commit history of a public GitHub repository. This is appropriate for intentionally public projects, but repositories containing internal code or sensitive documents need restricted visibility.
Potential impact
Unintended publication may expose internal code, configuration, or included secrets.
Remediation
Set visibility = "private" for an internal github_repository. Revoke and replace any secrets already exposed; making the repository private does not recover existing copies.
Examples
The examples change repository visibility to private. For intentionally public repositories, review the content and history before publication.
Before
hcl
resource "github_repository" "repo" {
name = "example"
description = "My awesome codebase"
visibility = "public"
}
After
hcl
resource "github_repository" "repo" {
name = "example"
description = "My awesome codebase"
visibility = "private"
}