GitHub Enterprise Cloud attack surface analysis
Pretty simple list that maps every potential abuse point or hardening opportunity in GitHub Enterprise Cloud, complete with direct links to GitHub’s documentation.
Account and profile management
Enterprise management
Organization management
Authentication
Authorization
Recommended by LinkedIn
Repositories management
Webhooks
Branch Protection
Tag Protection
Code Owners (ex. ./github/CODEOWNERS, ./gitlab/CODEOWNERS, etc. )
Audit logging