Control: 1.1.17 Ensure branch deletions are denied
Ensure that users with only push access are incapable of deleting a protected branch.
When enabling deletion of a protected branch, any user with at least push access to the repository can delete a branch. This can be potentially dangerous, as a simple human mistake or a hacked account can lead to data loss if a branch is deleted. It is therefore crucial to prevent such incidents by denying protected branch deletion.
Note: Protected branches cannot be deleted.
For each repository that is being used, verify that protected branches cannot be deleted.
For each repository that is being used, block the option to delete protected branches via branch protection rules.
Run the control in your terminal:
steampipe check github_compliance.control.cis_supply_chain_v100_1_1_17
Snapshot and share results via Steampipe Cloud:
steampipe loginsteampipe check --share github_compliance.control.cis_supply_chain_v100_1_1_17
This control uses a named query:default_branch_setting_block_deletion