The 36 GitHub security checks Black Cat runs
Black Cat SSPM evaluates 36 security policies against your GitHub configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect GitHub — what access Black Cat needs, and why.
Access control & privilege
21 checks · highest severity: critical
Configuration hardening
13 checks · highest severity: high
Access control & privilege (21)
- Org Default Permission Too Permissive severity: high
- Repo Branch Protection Disabled severity: critical
- Stale Organization Member severity: low
- Repo Admins Bypass Branch Protection severity: high
- Repo Stale Reviews Not Dismissed severity: medium
- Team Admin Permission severity: medium
- OAuth App Broad Repository Access severity: medium
- GitHub Actions Can Approve Pull Requests severity: high
- GitHub Actions Default Workflow Permissions Read-Write severity: high
- Org Members Can Fork Private Repos severity: medium
- Org Members Can Create Public Repos severity: medium
- Org Repository Creation Unrestricted severity: medium
- Repo Branch Deletion Allowed severity: high
- Repo Force Pushes Allowed severity: high
- Repo Insufficient Required Reviews severity: high
- Too Few Organization Owners severity: high
- Too Many Organization Owners severity: low
- Fine-Grained PAT Stale severity: medium
- Fine-Grained PAT Broad Access severity: high
- Copilot Allows Public Code Suggestions severity: medium
- Copilot Seat Inactive severity: low
Configuration hardening (13)
- Repo Secret Scanning Disabled severity: high
- Repo Dependabot Disabled severity: medium
- Public Repo Without Security Policy severity: medium
- Actions Allow All External severity: high
- Webhook Insecure URL severity: high
- Org Dependabot Alerts Disabled severity: medium
- Org Secret Scanning Disabled severity: high
- Actions Runner Allows Public Repos severity: high
- GitHub Actions Enabled For All Repositories severity: medium
- Org Web Commit Signoff Not Required severity: low
- Repo Secret Scanning Push Protection Disabled severity: high
- Actions SHA Pinning Not Required severity: medium
- Actions Selected-Actions Allowlist Pattern Unpinned severity: low
Other checks (2)
severity: critical Org 2FA Not Required fix difficulty: easy #
Require two-factor authentication for all GitHub organization members
- Navigate to GitHub Organization Settings > Authentication security
- Enable 'Require two-factor authentication for everyone'
- Set a grace period for existing members to enable 2FA
- Remind members they lose access to organization resources until they enable 2FA
- Outside collaborators that do not comply are removed and must be re-invited after enabling 2FA
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high Member Without 2FA fix difficulty: easy #
Contact GitHub organization members who have not enabled 2FA and direct them to enroll
- Contact the organization member to enable 2FA on their GitHub account
- Direct them to GitHub Settings > Password and authentication > Two-factor authentication
- Verify they regain access to organization resources after enabling 2FA
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4