> For the complete documentation index, see [llms.txt](https://docs.forestall.io/forestall/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/forestall/scans/policies/github-policies.md).

# GitHub Policies

**GitHub Policies**

GitHub Policies define security controls and assessment rules tailored for GitHub environments.\
These policies focus on analyzing identity-related risks, team and role assignments, repository access configurations, and access control mechanisms within GitHub organizations and enterprises.\
By using GitHub-specific policies, Forestall ISPM helps identify privilege misuse, risky identity and repository configurations, and exposure points in GitHub cloud identity infrastructures.

***

### Edit Scan Policy (GitHub)

This section allows users to configure scan settings specific to GitHub environments, including enabled modules, exclusions, and scan options.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-546e36f0e0cc1cdaa76065a7cdf7243a8150bdb2%2Fpolicies-github-policies-image-1.png?alt=media" alt=""><figcaption><p>GitHub Scan Policy Settings</p></figcaption></figure>

***

#### GitHub Scan Policy Settings

***

### Vulnerability Policies and Tiering (GitHub)

This section defines vulnerability policies and tiering configurations specific to GitHub environments. Vulnerability policies determine which GitHub-specific security checks are executed during the scan, while tiering helps identify critical cloud identities, teams, and roles based on their potential security impact.

***

### GitHub Scan Modules

**GitHub Assessment:** This module enables users to identify and evaluate vulnerabilities, misconfigurations, and security risks within their GitHub environment, including organizations, users, teams, repositories, organization roles, and app installations. It provides deep visibility into the organization configuration and access relationships across organizations and enterprises. As a core component of the engine for GitHub-based assessments, this module is a mandatory option.

**Tier 0 Analysis:** This module analyzes attack paths and privilege escalation routes within the GitHub environment to identify identities that can reach Tier 0 assets through dangerous permissions, team memberships, or role configurations.

***

**General Settings**

| Setting                           | Description                                                                              |
| --------------------------------- | ---------------------------------------------------------------------------------------- |
| **Include Public Repos**          | Include public repositories in the scan scope.                                           |
| **Include Archived Repos**        | Include archived (read-only) repositories in the scan scope.                             |
| **Include Forks**                 | Include forked repositories in the scan scope.                                           |
| **Include Outside Collaborators** | Include outside collaborators (non-members) as identities in the scan.                   |
| **Inactivity Threshold (days)**   | The number of days of inactivity after which a user is flagged as inactive (e.g., `90`). |

***

### Tier 0 Assets (GitHub)

Tier 0 Assets settings allow users to designate critical GitHub identities as privileged. Selected GitHub organizations, teams, users, and roles are treated as high-impact identities and are prioritized during privilege exposure and attack path analysis. Identities marked as Tier 0 Assets represent potential organization-level or enterprise-level compromise if misused or exposed.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-d8ac748c63f4fe656c53268075afbabe5376c9ca%2Ftier0.gif?alt=media" alt=""><figcaption><p>Adding Tier 0 Assets</p></figcaption></figure>
