Lesson 21 / 24

Cleaning Git History

Remove a file from every commit with git filter-repo and understand its limits.

Rewriting history

git filter-repo rewrites every commit so a file or string disappears from history. Because commit hashes change, everyone must re-clone and open pull requests must be recreated. It cleans your copy, but forks and caches may still hold the old data, which is why rotation comes first.

Remove a file everywhere

Run it on a fresh clone, then force-push. Back up first, and tell the team before you force-push a shared branch.

git clone git@github.com:acme/shop.git shop-clean && cd shop-clean
git filter-repo --path .env --invert-paths
git push --force --all

Quick check: Why must the secret still be rotated after cleaning history?

  • Cleaning always fails
  • Copies may exist in forks, clones and caches
  • Git requires it
  • The secret expires by itself
Answer

Copies may exist in forks, clones and caches — You cannot recall every copy, so only revocation makes the old value useless.