Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

If you pushed a real .env file or database credential to GitHub, revoke or rotate every exposed credential immediately. Treat it as compromised even if you deleted the file, made the repository private, or the exposure was brief. Then determine whether the secret reached GitHub: local-only commits need cleanup before pushing; pushed commits may require a coordinated history rewrite as well as credential rotation.

First: invalidate exposed credentials

Identify every value in the file that grants access, including database passwords, API tokens, cloud keys, and signing keys. Revoke or rotate each one through the service that issued it. GitHub advises: “Consider the secret compromised, even if only exposed for a second, and revoke the secret immediately.” GitHub Docs: Storing your secrets safely.

Invalidate the old credential before creating and deploying a replacement. For database credentials, review the provider’s activity logs for unexpected use and check what permissions the exposed account had. A private repository can limit who sees the source, but it does not invalidate a credential or establish that nobody copied it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep the file out of future commits

Stop tracking the local file and ignore it so a later commit does not add it again. For example, from the repository root:

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
git rm --cached .env
echo .env >> .gitignore
git add .gitignore
git commit -m "Stop tracking local environment file"

git rm --cached removes the file from Git’s index but leaves your local copy in place. If your file is in a different path, use that path in both commands. Check that the ignore rule matches the actual filename or location.

You can provide an .env.example containing variable names and dummy values for teammates, but do not copy real credentials into it. Put values needed by deployment or automation in environment variables or an approved secret-management feature, and use the narrowest permissions the credential needs. GitHub’s guidance covers safe secret storage and least-privilege access.

Ignoring a file prevents future untracked copies from being added; it does not remove a file from commits already made.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Find out whether the secret was pushed

If the commit is only on your computer

Remove the secret from every affected local commit before pushing. If it is in your latest commit, edit the file, stage the safe version, and amend the commit:

git add .env .gitignore
git commit --amend

This example assumes the corrected file should remain tracked; if the file should not be tracked, remove it from the index and stage the ignore rule instead. Inspect the commit before pushing to confirm it contains no secret. If the secret appears in earlier local commits too, rewrite those commits as well. GitHub’s command-line guidance says a blocked push must be cleaned in every commit where the secret appears: Working with push protection from the command line.

Do not use git revert as a secret-removal method. A revert adds a new commit that undoes changes in the working tree, but leaves the original secret-bearing commit in history. GitHub explains the distinction in its data-leak prevention guidance.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

If the commit reached GitHub

Rotate or revoke the credential first, then decide whether to rewrite repository history. Removing .env in a later commit cleans the current version of the file, not the earlier commit that contained it. This applies whether the repository is public or private.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

GitHub documents using git-filter-repo to remove a sensitive file or replace secret text throughout history. Follow the current GitHub instructions for removing sensitive data, then inspect the rewritten history and affected references before force-pushing. A rewrite changes commit IDs for affected commits and their descendants, so coordinate with collaborators before replacing shared history.

Plan the history rewrite with collaborators

A force-push updates the remote references; it does not ensure every copy of the old commit disappears. Existing clones, branches, forks, pull requests, cached views, and stored Git objects may still contain the data. Old work can also reintroduce the tainted history if someone pushes an outdated branch.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Tell collaborators which branches or commits are affected and when the rewrite will happen.
  • Have collaborators clean their old clones or re-clone after the rewrite. GitHub recommends rebasing work based on tainted history rather than merging it back.
  • Coordinate with owners of relevant forks, which can retain old commits.
  • Plan any temporary changes to branch protection or permissions carefully, and do not invite pushes from old references.
  • For cached views or references GitHub controls, follow its guidance on contacting Support. GitHub notes that assistance is limited to sensitive data when rotating the credential cannot mitigate the risk.

These limitations and coordination steps are covered in GitHub’s sensitive-data removal documentation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If GitHub blocked the push

Push protection can stop supported secrets before they enter a protected repository. Remove the secret from every affected commit, then retry the push. For a secret in the latest commit, amend it; for secrets in older commits, rewrite those too. A block is not a reason to push the real value anyway.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Detection coverage and availability depend on repository and account settings and plan. GitHub also describes user-level push protection for pushes to public repositories. See command-line push protection and GitHub’s push protection overview for current behavior and scope.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Check for misuse and reduce the chance of a repeat

Investigate the exposure

Review activity logs from the database or service whose credential leaked. If GitHub tokens or organization activity may be involved, review relevant secret-scanning alerts and audit-log events, including unexpected actors or IP addresses where those details are available. GitHub outlines incident response in its security incident guidance and investigation areas.

Record the exposure window, affected credential identities, revocation time, repository visibility, and suspicious activity. Do not copy the secret into incident notes.

Add preventive controls

  • Enable secret scanning and push protection where available, and consider requiring relevant alerts to be resolved before a pull request is merged. Availability and coverage depend on GitHub settings and plan; see GitHub’s leak-prevention how-tos.
  • Use short-lived or expiring credentials when the issuing service supports them, and grant credentials only the access they need.
  • Keep secrets in environment variables or approved secret-management features rather than source files, and avoid logging secret values.
  • Use a dummy-value example file for shared configuration, and verify that local secret files are ignored before committing.

GitHub’s secret-scanning documentation describes detection and remediation. Scanning can help find exposed values, but it does not replace revoking a credential that was already exposed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.