Keys and secrets · 4 of 20

Rotate first, then rewrite history. Deleting the file does nothing

Our code and the research
Check it
git log -p -S "sk_live_" --all | headgit log -p --all -G "[0-9]{4}[- ]?[0-9]{4}[- ]?[0-9]{4}[- ]?[0-9]{4}" | grep -cE "^\+"
Free, no call

Get every Fix AI Slop Code episode

The code it wrote, the code it should have written and a check, for every episode

Free, straight to your inbox. No call, no pitch

What is going on

A commit that removes a secret leaves it in every prior commit, every clone, every fork, and GitHub's cached views of deleted forks. A leaked key on GitHub or Docker Hub is tried within minutes. 64 percent of valid secrets leaked in 2022 were still valid in January 2026.

Where it bit

A personal phone number in commented-out JSX in the portfolio, in history forever. TruffleHog pulled 40 valid keys out of deleted forks in one study.

The practice

Rotate the credential first, because the scrub is cosmetic until you do. Then git filter-repo --sensitive-data-removal, force push, and a support ticket for cached views. Push protection on every public repo so it cannot happen again.

Free, no call

Get this check as a script you can run tonight

Free, straight to your inbox. No call, no pitch

What to do with this

If this check came back with more than you expected, that is worth a conversation

Book a free 30-minute call