Rotating Leaked GitHub Secrets: Deleting Commits Doesn't Scrub Git History
eyishazyer · x · 2026-09-17
Part 5 of a GitHub security thread: don't ignore secret scanning alerts. Rotate flagged credentials immediately—deleting the commit doesn't remove it from git history. Check Settings → Code security to confirm scanning is on. Quoted part 4: protect main with required reviews and blocked force pushes to limit blast radius of a compromised account.
Related event: GitHub Security Audit: Rotate Leaked Secrets, Don't Just Delete Commits(2 posts)→
More from coding & agent
- LangChain Rebuilds LangSmith Trace Filtering for Faster Agent Observability — LangChain · 2026-09-18
- LangChain rebuilds LangSmith trace filtering for faster, more precise agent debugging — LangChain · 2026-09-18
- Dev: The Smartest Model Isn't the Best at Writing Simple, Mergeable Code — timigod · 2026-09-18
- LinkedIn to present a PyTorch-native GPU retrieval engine powering feed and search — PyTorch · 2026-09-18
- Jev + Kimi K3 cascade classifies 100 fraud emails at 96% accuracy for $0.07 — nutlope · 2026-09-17
- AWS compares Bedrock RAG vector stores: OpenSearch vs pgvector vs S3 Vectors — AWS ML Blog · 2026-09-17