Cannot delete sensitive data in lost commit after rebasing

Viewed 68

I accidentally pushed the file that contains API key information to the master branch and tried to "delete" the commit that contains the sensitive info. So I used git rebase and force push to go back to several commits before the sensitive one. I thought I have completely removed that sensitive commit, but indeed it is still in history. After rebasing, I have already made several new pushes, and when I notice the sensitive data is still there, I can no longer edit that commit any more. And the function is suspended for privacy protection.

I tried bfg cleaning, and was told "unable to edit hidden commit," and tried cherry pick but get the error message "fatal: bad revision."

I contacted GitHub support, but no one's answering my ticket. I don't know what to do right now. How can I go back to that sensitive commit which is lost after rebasing?

1 Answers

For security reasons you should definitely revoke that API key as soon as possible to prevent any misuse. Someone could already have copied the API key. After you have done that, you could reset your branch to the commit just before commiting your API key.

To do so, first find the commit ID just before adding the credential. Inside your branch, then perform the following command to reset your local branch to that commit.:

git reset --soft <commit id before leak>

All the work you have done after this commit will remain available in your local directory and you can create a new commit out of it.

By doing a force push afterwards, the leaked credential should no longer be visible when browsing the history e.g. on GitHub. If someone already knows the commit ID of your credential leak, it might however still be possible to access the commit. Therefore revoking the credential is unfortunately the only real solution.

Related