If you found a similar mistake in your repository, you can delete commit from history using: `git rebase --onto <commit-id>^ <commit-id>`. Or if you want actually rewrite it, see git rebase -i` documentation.
E: Oh, and just to preempt this, even saying "i use only random passwords with no pattern" is useful information, as is having a ballpark password length.
Call me selfish, but if my password is known to be too tough to bother, so Eve moves on to someone else's weak password, great.
If the keys/passwords are already pushed to GitHub or other public hostin, they should also be revoked.
Just revoke the password/secret/whatever.
Squash merges are just bad. They destroy all the info that makes git handle branching and conflicts better than svn.
<commit-id>^ <commit-id>
is
<commit-id>^!
I use it all the time with:
git diff <commit-id>^!