Control: 1.1.16 Ensure force push code to branches is denied
The "force push" option allows users with "push" permissions to force their changes directly to the branch without a pull request, and thus should be disabled.
The "force push" option allows users to override the existing code with their own code. This can lead to both intentional and unintentional data loss, as well as data infection with malicious code. Disabling the “force push” option prohibits users from forcing their changes to the main branch, which ultimately prevents malicious code from entering source code.
Note: Users cannot "force push" to protected branches.
For each repository in use, validate that no one can "force push" code.
For each repository in use, block the option to "force push" code.
Run the control in your terminal:
steampipe check github_compliance.control.cis_supply_chain_v100_1_1_16
Snapshot and share results via Steampipe Cloud:
steampipe loginsteampipe check --share github_compliance.control.cis_supply_chain_v100_1_1_16
This control uses a named query:default_branch_blocks_force_push