Check out OpenSSF's "Source Code Management Platform Configuration Best Practices" and Legitify - a cli tool that helps you comply - eviltoast