# Cleaning Git History — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/leak-git-history

> Remove a file from every commit with git filter-repo and understand its limits.

## Rewriting history

`git filter-repo` rewrites every commit so a file or string disappears from history. Because commit hashes change, everyone must re-clone and open pull requests must be recreated. It cleans your copy, but forks and caches may still hold the old data, which is why rotation comes first.

## Remove a file everywhere

Run it on a fresh clone, then force-push. Back up first, and tell the team before you force-push a shared branch.

```bash
git clone git@github.com:acme/shop.git shop-clean && cd shop-clean
git filter-repo --path .env --invert-paths
git push --force --all
```

**Quiz:** Why must the secret still be rotated after cleaning history?

- [ ] Cleaning always fails
- [x] Copies may exist in forks, clones and caches
- [ ] Git requires it
- [ ] The secret expires by itself

*Answer:* Copies may exist in forks, clones and caches. You cannot recall every copy, so only revocation makes the old value useless.
