CLI tool that finds secrets accidentally committed to a Git repo (2017)
github.com
github.com
Title as of my reading was "CLI tool that finds secrets accidentally committed to a Git repo (2017)".
* performance (powered by go-git)
* scan github orgs/users
* ref targeting
E.g. when I have a line saying
printf("debug: now at: %d\n", i); /* DONTCOMMIT */
then when I type "git commit ...", a script will be invoked that will recognize the "DONTCOMMIT" string, and it will abort the commit. if test $(git diff --cached -z $against | grep $marker | wc -c) != 0
may be changed to if git diff --cached -z $against | grep -q $markerAdditionally, GitLab has push rules[0] that help preventing pushing secrets (based on filenames).
[0]: https://gitlab.adhoc-gti.com/help/push_rules/push_rules#prev...
https://help.github.com/articles/removing-sensitive-data-fro...
That's misleading. Once you commit and push it to a remote, you should consider it compromised. You could remove it from the repo and force-push to re-write history, but anyone could have pulled from the same remote since your original push and have the file locally on their system.
A better option is to push a new commit to remove the file from the repo (add to .gitignore), then set a new, strong passphrase/whatever and don't ever use the one you pushed again.
Warning: Once you have pushed a commit to GitHub, you should consider any data it contains to be compromised. If you committed a password, change it! If you committed a key, generate a new one.