policy name: enterprise_allows_creating_public_repos
severity: MEDIUM
The enterprise's repository creation policy should be set to private/internal repositories only. This will prevents non-admin users from creating public repositories and potentially exposing source code.
Users can accidentaly create public repositories and expose source code.
- Make sure you are an enterprise owner
- Go to the policies page
- Under the "Repository creation" section
- Choose the "Members can create repositories" option and uncheck 'Public'