Source code repository and secrets procedure
Download this document free
Get this document with your free trial. Choose from the full Complyzard library.
Try 1 month free30 days free, then $19/month. Trial terms apply. Card required. Cancel anytime.Document information
For development, platform and security owners to control repository access, protected branches, reviews, service identities, secrets, change evidence and recovery.
- Document type
- Procedure
- Format
- DOCX
- Pages
- 9
- Language
- English
- Version
- 1.0
- Updated
- 2026-09-15
- Category
- Information security
- Licence
- Internal use
Description
For development, platform and security owners to control repository access, protected branches, reviews, service identities, secrets, change evidence and recovery.
Contents
- Document control
- Purpose of this procedure
- Define the repository profile
- Separate repository permissions
- Select the repository protection profile
- Challenge the profile before approval
- Onboard people and automation separately
- Control forks and external contributions
- Trace contributions to release artifacts
- Control dependencies and generated build artifacts
- Secure build and automation runners
- Respond to exposed secrets
- Control temporary bypass
- State the limits of repository evidence
- Migrate, archive, or delete repositories
- Rehearse loss of the hosting platform
Version history
- v1.015/09/2026