Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,293,244
Community Members
 
Community Events
165
Community Groups

Best practices for setting up & securing a BitBucket Mercurial repo

Edited

What are the best practices for setting up and for securing all aspects of a BitBucket Mercurial repo (hosted on bitbucket.org), including access, ensuring simplified commit histories and branch heads, etc.?

For pushes, can I:

  1. Forbid creating more than one head per branch
  2. Forbid commits from users whose user name does not exactly match a BitBucket account, either matching by email address alone, or also including the full name?  Can I restrict the email address (& possibly full name) to that of the approved BitBucket account at the time when that account was authorized  (i.e., the BitBucket account email address and full name cannot have changed)
  3. Require that all commits are digitally signed, either via the Commitsigs extension, or via some other mechanism
  4. Require that all pushed heads build successfully, pass all tests, and conform to formatting / linting standards
  5. Use the ACL extension to allow / deny access to particular users for particular files
  6. Require that no files that match any .hginore patterns are ever committed

Obviously there are other components of setup & security.  It would be great to compile a comprehensive guide.  Other potential practices include:

  1. requiring two-factor authentication
  2. requiring ed25519 ssh keys
  3. enabling ssh compression
  4. assigning repos to projects within teams

0 comments

Comment

Log in or Sign up to comment
TAGS
Community showcase
Published in Bitbucket

Git push size limits are coming to Bitbucket Cloud starting April 4th, 2022

Beginning on April 4th, we will be implementing push limits. This means that your push cannot be completed if it is over 3.5 GB. If you do attempt to complete a push that is over 3.5 GB, it will fail...

2,084 views 2 9
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you