Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The problem here is that GitHub keeps the ref logs even for commits that no longer exist.

I don’t see how BFG helps here



it rewrites the history. Isn't that really enough? You can remove all the keys from the git history. and I agree , i forget the point about rotating the key which i do always in first .


No it’s not enough. Read the article and it will explain why.

Also, if you’re going to rotate your secrets (which you absolutely should do regardless) then everything else is pointless because it’s now just an invalid credential.


It might remove it from your local repo, but not from GitHub, that's the point.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: