Lesson 21 / 24
Cleaning Git History
Remove a file from every commit with git filter-repo and understand its limits.
Rewriting history
git filter-repo rewrites every commit so a file or string disappears from history. Because commit hashes change, everyone must re-clone and open pull requests must be recreated. It cleans your copy, but forks and caches may still hold the old data, which is why rotation comes first.
Remove a file everywhere
Run it on a fresh clone, then force-push. Back up first, and tell the team before you force-push a shared branch.
git clone git@github.com:acme/shop.git shop-clean && cd shop-clean
git filter-repo --path .env --invert-paths
git push --force --allQuick check: Why must the secret still be rotated after cleaning history?
- Cleaning always fails
- Copies may exist in forks, clones and caches
- Git requires it
- The secret expires by itself
Answer
Copies may exist in forks, clones and caches — You cannot recall every copy, so only revocation makes the old value useless.