Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If a credential was committed to Git or otherwise exposed, treat it as compromised: deleting it from the current file does not revoke it or erase copies in Git history. First identify the credential and its access, then revoke or rotate it, update every dependent system, investigate for misuse, and decide separately whether Git history needs cleanup.

How do you find and scope an exposed secret?

Start with the alert or suspected exposure, but do not paste the credential into tickets, chat, or another search tool to investigate it. Record enough information to identify the incident without spreading the value: the secret type, repository or service, affected branch or commit, approximate exposure period, and the systems or permissions it may involve.

Confirm the finding and its reach

  • Determine whether the finding is a real credential, what provider or system issued it, whether it is still active, and what it can access.
  • Search the repositories, workflows, logs, cloud services, and other locations that fall within the suspected scope for the same credential or related credentials.
  • Check relevant branches and commit history. GitHub Secret Scanning can detect supported credential patterns in repository Git history across branches. GitHub also describes scanning for issues, pull requests, discussions, wikis, and secret gists; actual coverage depends on repository type, configuration, and enabled features.
  • Use provider-specific and custom patterns where they help cover credentials that a generic pattern may not detect. Generic patterns can produce noisier findings, so validate alerts without unnecessarily exposing the secret value.

A scanner alert is an investigation lead, not proof that a credential was used maliciously. Conversely, an alert that is uncertain or appears to be a false positive is not a reason to leave a potentially exposed credential active without checking it.

What should you do immediately after finding an exposed credential?

Contain access and rotate through the issuing provider

Revoke or rotate the credential promptly using the provider’s supported procedure for that credential type. GitHub Docs advises rotating an affected credential immediately when an alert arrives; its incident guidance recommends rotation when exposure is possible even if compromise is uncertain. The right procedure depends on the credential: do not assume every provider supports overlapping old and new credentials, or that one generic command is safe for all cloud keys and tokens.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Before revocation, establish how affected services will receive the replacement and test the change where practicable. Follow the provider’s instructions so you do not create an avoidable outage by revoking a credential while production still depends on it.

Replace the value wherever it is used

Inventory every consumer of the old credential, then update each one with the replacement. Depending on your setup, that can include application deployments, CI/CD workflows, repository or organization secrets, environments, and other services or integrations. Do not assume that changing a value in one repository updates copies held elsewhere.

Rank #2
Sale
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  1. Generate or provision the replacement using the issuing provider’s supported process.
  2. Update each dependent system and deployment with the replacement, keeping the old credential available only as long as the provider’s procedure and safe transition require.
  3. Test the affected services and workflows with the new value.
  4. Revoke the exposed credential if it has not already been revoked, and confirm the old value no longer grants access where the provider allows that check.

How do you check whether the exposed secret was misused?

Review the provider’s relevant audit and access logs and repository activity for actions associated with the credential during the exposure period. Look for unexpected access, changes, or other activity relevant to what the credential could do. Use the credential’s permissions to set the investigation’s scope: a read-only token and an administrative key do not represent the same potential impact.

Assess likely impact and involve security, engineering, legal, or privacy stakeholders as warranted by the systems and data involved. After replacement, monitor relevant logs, verify that dependent services continue to work, and confirm that the associated secret-scanning alert is resolved. Record the incident and the actions taken so responders can track outstanding work.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Does deleting a secret from Git remove it from history?

No. Removing a credential from the latest version of a file does not remove earlier committed versions, invalidate the credential, or eliminate copies already made elsewhere. Credential rotation is the control that prevents the exposed value from continuing to work; rewriting Git history is a separate cleanup decision.

When history rewriting may be warranted

After the credential has been revoked or rotated, rewriting history may not be needed to stop that credential from working. It can still be appropriate when the sensitive value itself must be removed from the repository’s visible history, subject to the hosting service’s policies and a coordinated cleanup plan.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Rewriting changes commit hashes and can affect collaborators, signatures, and pull-request views. It does not automatically remove copies in clones, forks, cached views, or references to old commits. GitHub’s documentation describes using git-filter-repo for history rewriting and recommends coordinating with collaborators; branches based on the old history should be rebased rather than merged back in a way that restores tainted commits.

Plan a rewrite before force-pushing

  1. Check the hosting service’s current guidance and the current git-filter-repo manual before making destructive changes. GitHub’s current documentation describes the --sensitive-data-removal option and states that it requires git-filter-repo version 2.47 or later.
  2. Make a fresh clone or backup, identify all affected references, and coordinate the rewrite and force-push with repository owners and collaborators.
  3. For removing a file from history, GitHub documents --invert-paths --path. Include every historical path if the file was moved or renamed. Adapt the operation to the actual exposure; do not run a rewrite command against a production repository without confirming its scope and effects.
  4. After rewriting, coordinate collaborator cleanup so old clones do not reintroduce the previous history. Contact GitHub Support about hosted cached views or pull-request references where applicable.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can you prevent another secret from reaching Git?

Use repository secret scanning and, where available, push protection to detect supported patterns before they spread. These controls have different coverage and may depend on repository configuration, permissions, and hosting plan; verify what is enabled for the repositories you need to protect. Keep runtime credentials out of committed source files and supply them through environment variables or a secrets-management service. Examples named by GitHub include Azure Key Vault, AWS Secrets Manager, and HashiCorp Vault.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

When evaluating controls, compare the surfaces they cover, their support for provider-specific, generic, and custom patterns, whether they detect secrets before or after a push, how findings are validated, how they fit existing identity and incident workflows, and what plan or configuration is required. These are selection criteria, not a product ranking.

  • Use least-privilege credentials so an exposed secret has only the access it needs.
  • Keep credentials in managed runtime configuration rather than source files, and restrict who can view or change them.
  • Enable the scanning and push controls available for your repository and review relevant alerts and audit activity.
  • Make credential ownership and dependent systems discoverable so responders can rotate a value without guessing where it is used.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.