If you pushed a real secret to GitHub, revoke or rotate it first—even if the repository is private or you have already deleted the file. Removing `.env` from the current version does not remove it from earlier commits. After containment, determine whether the secret reached GitHub, clean the relevant history when appropriate, and prevent the same value from being committed again.
What to do first: invalidate every exposed credential
Assume every real credential in the exposed file is compromised. GitHub’s guidance is direct: “Consider the secret compromised, even if only exposed for a second, and revoke the secret immediately.” GitHub Docs: Storing your secrets safely recommends revoking exposed secrets rather than relying on file deletion.
As an Amazon Associate I earn from qualifying purchases.
Make a list of the values that could grant access—database usernames and passwords, cloud keys, API tokens, signing keys, and other credentials—and revoke or rotate each one with the service that issued it. Invalidate the old credential before creating and distributing a replacement. Store replacement values in environment variables or an approved secret-management feature, not in the repository.
For a database credential, check the database provider’s activity logs for unexpected access and consider whether its permissions were broader than necessary. Keep incident notes such as the affected credential, likely exposure window, revocation time, repository visibility, and suspicious activity. Do not paste the secret itself into those notes. GitHub’s security incident response guidance covers containment and investigation.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Did the secret reach GitHub?
If the commit is still local
Remove the secret from every affected local commit before pushing. If it is only in your latest commit, edit the file, stage the safe version, and amend the commit; if it appears in earlier local commits, rewrite those commits as needed. A blocked push must be corrected in every commit containing the secret, not just the latest one. See GitHub’s instructions for working with push protection from the command line.
Do not use git revert as a secret-removal method. A revert adds a new commit that undoes the visible change, but the original secret-bearing commit remains in history. GitHub explains this distinction in its data-leak prevention guidance. If the credential was never pushed and no one else could access it, rewrite the local history and verify the secret is gone before publishing.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
If the commit was pushed
Rotate the credential whether the repository is public or private. A private setting limits who can view the repository; it does not invalidate the credential or establish that no other copies exist. Then decide whether to rewrite history. GitHub’s sensitive-data removal guidance documents using git-filter-repo to remove a sensitive file or replace secret text throughout repository history.
When and how to clean pushed history
Credential rotation addresses whether the exposed value still works. History rewriting addresses whether it remains in the repository’s reachable history. Rewriting is often warranted for sensitive data, but it is not a substitute for revocation and it has coordination costs: affected commit IDs and their descendants change, and collaborators’ old work can conflict with or reintroduce tainted history.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Contain first. Revoke or rotate the exposed credentials before undertaking repository cleanup.
- Follow GitHub’s current rewrite procedure. Use the documented
git-filter-repoworkflow for the file or text involved; inspect the resulting history and affected refs before pushing changes. - Coordinate the rewrite. Tell collaborators which branches are affected and when the rewritten history will be available. Plan any necessary branch-protection changes deliberately, and do not accept pushes based on old refs after the rewrite.
- Have collaborators clean up old clones. They should follow GitHub’s instructions for the rewrite and rebase work based on tainted history rather than merging old branches in a way that restores the affected commits. Re-cloning may be the safest option for some collaborators.
- Check copies beyond the main repository. Forks, pull requests, cached views, and other retained references may still expose the old data. Coordinate with fork owners where relevant. For cached views or references that require GitHub’s help, consult the sensitive-data removal guidance; GitHub Support’s assistance is limited to cases where sensitive data cannot be made safe through credential rotation.
A force-push changes the remote branch history; it does not guarantee that every copy of the old commits disappears. The remaining risk depends on where those commits were copied or retained, so cleanup needs to account for more than the repository’s latest tree.
Remove the local .env file from tracking
After handling the exposed value, stop Git from tracking the local configuration file and add its path to `.gitignore` so it is not accidentally added again. For example, if the file is at the repository root, add this line to `.gitignore`:
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
.env
Then remove the file from Git’s index while keeping your local copy:
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsgit rm --cached .env
git add .gitignore
git commit -m "Stop tracking local environment file"
Adjust the path if the file is elsewhere. This removes it from the next version of the repository; it does not erase earlier commits. Keep an `.env.example` only if it contains variable names and dummy values—never copy working credentials into it. If a build, deployment, or CI workflow needs secrets, provide them through the platform’s secret-management settings or environment variables.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
If GitHub blocks your push for a secret
Push protection can stop certain supported secrets from entering a protected repository. When a push is blocked, remove the detected value from every affected commit and retry the push; amending only the latest commit will not help if another commit in the push still contains it. GitHub’s command-line push protection instructions explain the correction workflow.
If the detected value is a real credential, do not bypass the block just to get the push through. Remove it and use a safe secret store. Push protection’s availability depends on repository and account settings, plan, and supported secret types. GitHub also describes user-level push protection for pushes to public repositories; see its documentation on push protection and command-line push protection.
Quick Recap
Check for misuse and reduce the chance of another leak
Investigate the exposed credential
- Review the database or service provider’s activity logs for unfamiliar access, requests, or changes.
- If a GitHub token or organization activity may be involved, review available secret-scanning alerts and relevant audit-log events. GitHub lists investigation areas in its incident investigation guidance.
- Record useful facts about the incident without reproducing the secret.
Build safer defaults
- Use environment variables or platform secret-management features for runtime and deployment secrets, and grant credentials only the permissions they need. GitHub’s secret-storage guidance also recommends short-lived or expiring credentials where supported.
- Enable secret scanning and push protection where they are available for your account and repositories. Coverage and settings vary; GitHub documents secret scanning and leak-prevention options.
- Where your settings support it, consider requiring secret-scanning alerts to be resolved before a pull request can merge.
- Keep secret values out of source code, example configuration files, logs, and incident notes. Never bypass a protection block for a real credential; remove the value and push the corrected commits.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




