Source code repository and secrets procedure

Document preview9 pages
Cover of Source code repository and secrets procedure
Page 1 of 9

Download this document free

Get this document with your free trial. Choose from the full Complyzard library.

Try 1 month free30 days free, then $19/month. Trial terms apply. Card required. Cancel anytime.
Document information

For development, platform and security owners to control repository access, protected branches, reviews, service identities, secrets, change evidence and recovery.

Document type
Procedure
Format
DOCX
Pages
9
Language
English
Version
1.0
Updated
2026-09-15
Description

For development, platform and security owners to control repository access, protected branches, reviews, service identities, secrets, change evidence and recovery.

Contents
  • Document control
  • Purpose of this procedure
  • Define the repository profile
  • Separate repository permissions
  • Select the repository protection profile
  • Challenge the profile before approval
  • Onboard people and automation separately
  • Control forks and external contributions
  • Trace contributions to release artifacts
  • Control dependencies and generated build artifacts
  • Secure build and automation runners
  • Respond to exposed secrets
  • Control temporary bypass
  • State the limits of repository evidence
  • Migrate, archive, or delete repositories
  • Rehearse loss of the hosting platform
Version history
  • v1.015/09/2026
Report this document