Rotating Leaked GitHub Secrets: Deleting Commits Doesn't Scrub Git History

eyishazyer · x · 2026-09-17

Part 5 of a GitHub security thread: don't ignore secret scanning alerts. Rotate flagged credentials immediately—deleting the commit doesn't remove it from git history. Check Settings → Code security to confirm scanning is on. Quoted part 4: protect main with required reviews and blocked force pushes to limit blast radius of a compromised account.

Related event: GitHub Security Audit: Rotate Leaked Secrets, Don't Just Delete Commits(2 posts)→

Original post →

More from coding & agent

coding & agent channel →