Accidentally Committed Secrets to Git?
Deleting a file and creating a new commit does not remove it from Git history. Anyone who clones your repo can inspect past commits. Follow this 4-step emergency triage guide to erase the leak completely.
Automated bots scan GitHub public commit events within 120 seconds of pushing. If you leaked a Stripe, OpenAI, Anthropic, or AWS key, assume it is already compromised.
Customize Target File to Erase
.env, .env.local, service-account.json, id_rsagit filter-branch is officially deprecated by the Git project because it is slow and corrupts submodules. We use git-filter-repo, the modern high-speed Python standard.
Why git rm Is Not Enough
When you run git rm .env && git commit, you create a new commit saying "file deleted". But Git keeps the entire history of every file. Anyone can run git checkout HEAD~1 and read the old file.
git filter-repo rewrites every historical commit to pretend the file never existed from day one.
# On macOS with Homebrew: brew install git-filter-repo # Or with Python pip: pip install git-filter-repo# 1. Create a safe backup branch just in case
git branch backup-before-purge
# 2. Completely erase ".env" from all historical commits
git filter-repo --invert-paths --path ".env" --forcegit remote add origin <your-git-remote-url>
git push origin --force --all
git push origin --force --tagsPillar 1 of our 108 launch criteria scans your entire repository history for lingering Stripe keys, AWS tokens, and database passwords. Check your entire repo with the Founder Pass ($15 one-time).