Review GitHub repository visibility

Choose visibility according to the repository’s content and intended audience.

Description

Anyone can view the code and commit history of a public GitHub repository. This is appropriate for intentionally public projects, but repositories containing internal code or sensitive documents need restricted visibility.

Potential impact

Unintended publication may expose internal code, configuration, or included secrets.

Remediation

Set visibility = "private" for an internal github_repository. Revoke and replace any secrets already exposed; making the repository private does not recover existing copies.

Examples

The examples change repository visibility to private. For intentionally public repositories, review the content and history before publication.

Before

hcl
resource "github_repository" "repo" {
  name        = "example"
  description = "My awesome codebase"
  visibility  = "public"
}

After

hcl
resource "github_repository" "repo" {
  name        = "example"
  description = "My awesome codebase"
  visibility  = "private"
}

References