Home/Tools/Git Secret Leak Emergency Guide
Emergency Developer Action Guide

Accidentally Committed Secrets to Git?

Deleting a file and creating a new commit does not remove it from Git history. Anyone who clones your repo can inspect past commits. Follow this 4-step emergency triage guide to erase the leak completely.

STEP 0: Rotate the Leaked Key on Your Provider Dashboard First!

Automated bots scan GitHub public commit events within 120 seconds of pushing. If you leaked a Stripe, OpenAI, Anthropic, or AWS key, assume it is already compromised.

Go to your provider dashboard right now and revoke the key. Once revoked, proceed with purging Git history below.

Customize Target File to Erase

Common leak targets: .env, .env.local, service-account.json, id_rsa
Tool: git-filter-repo (Recommended)

git filter-branch is officially deprecated by the Git project because it is slow and corrupts submodules. We use git-filter-repo, the modern high-speed Python standard.

Why git rm Is Not Enough

When you run git rm .env && git commit, you create a new commit saying "file deleted". But Git keeps the entire history of every file. Anyone can run git checkout HEAD~1 and read the old file.

git filter-repo rewrites every historical commit to pretend the file never existed from day one.

1Install git-filter-repo
# On macOS with Homebrew: brew install git-filter-repo # Or with Python pip: pip install git-filter-repo
2Erase .env from Commit History
# 1. Create a safe backup branch just in case
git branch backup-before-purge

# 2. Completely erase ".env" from all historical commits
git filter-repo --invert-paths --path ".env" --force
3Force Push Cleaned Tree to GitHub
git remote add origin <your-git-remote-url>
git push origin --force --all
git push origin --force --tags
Want to confirm zero lingering secrets remain?

Pillar 1 of our 108 launch criteria scans your entire repository history for lingering Stripe keys, AWS tokens, and database passwords. Check your entire repo with the Founder Pass ($15 one-time).