# Git History साफ़ करना — डेवलपर्स के लिए 1Password और Secrets Hygiene

Source: https://www.geekswithgeeks.com/hi/secrets-hygiene/leak-git-history

> `git filter-repo` से फ़ाइल को हर commit से हटाएँ और उसकी सीमाएँ समझें।

## History दोबारा लिखना

`git filter-repo` हर commit को दोबारा लिखता है ताकि कोई फ़ाइल या string history से गायब हो जाए। Commit hashes बदलने से सबको दोबारा clone करना होता है और खुले pull requests दोबारा बनाने पड़ते हैं। यह आपकी copy साफ़ करता है, पर forks और caches में पुराना डेटा रह सकता है, इसीलिए rotation पहले आता है।

## फ़ाइल को हर जगह से हटाएँ

इसे नए clone पर चलाएँ, फिर force-push करें। पहले backup लें, और साझा branch पर force-push से पहले टीम को बताएँ।

```bash
git clone git@github.com:acme/shop.git shop-clean && cd shop-clean
git filter-repo --path .env --invert-paths
git push --force --all
```

**Quiz:** History साफ़ करने के बाद भी secret क्यों बदलना चाहिए?

- [ ] सफ़ाई हमेशा विफल होती है
- [x] Forks, clones और caches में copies हो सकती हैं
- [ ] Git इसे ज़रूरी करता है
- [ ] Secret अपने आप expire होता है

*Answer:* Forks, clones और caches में copies हो सकती हैं. हर copy वापस नहीं बुलाई जा सकती, इसलिए सिर्फ़ रद्द करना पुराने मान को बेकार बनाता है।
