Unreachable commit #209559
Replies: 5 comments
This comment was marked as low quality.
This comment was marked as low quality.
|
Hey, I'm not GitHub staff, so take this as what I understand from the docs. Support can confirm the details. Treat the data as already leaked. Revoke or change any passwords, tokens, or keys that were in the commit first. That matters more than the removal. If the commit is still in a branch or pull request, you'll want to clean that history too (git filter-repo is the usual tool) before asking Support to purge it. |
|
Rewriting history and force pushing is only the first half. Per GitHub's docs on removing sensitive data, the old commits can still be reachable through clones or forks, directly by their SHA in cached views, and through pull requests that reference them. For the GitHub-hosted copies, the documented path is to contact GitHub Support through the support portal and ask for the cached views and the references in pull requests to be removed. GitHub is explicit that Support will only assist with removal of sensitive data, and the exposed credential should be treated as compromised and rotated, since that is the part that actually closes the hole. Data in other people's clones and forks cannot be removed by GitHub at all. On your process questions: this removal is not self-serve from the repository UI, it goes through a Support ticket. Whether Support needs any temporary access, or notifies the repository owner, is something they confirm on the ticket; the docs do not promise either, so I would not assume. |
|
Hi! GitHub distinguishes between making a commit unreachable and removing sensitive data that may still be accessible through cached views or references. If an unreachable commit contains sensitive information, the general process is:
Regarding your questions:
Simply making a commit unreachable does not guarantee that sensitive data has been removed from GitHub's cached views or other references. Official documentation: I hope this helps! |
|
Quick heads up: an unreachable commit isn’t gone just because no branch points to it. Anyone with the full SHA can still open it through cached views, and old pull request references can keep it alive too. So the cleanup has a few parts, and the first one has nothing to do with GitHub.
On your three questions: Owner approval: GitHub’s docs don’t lay down a fixed rule. File the ticket from the owner’s account or an admin account and you avoid any back and forth. The official walkthrough is “Removing sensitive data from a repository” in GitHub Docs. |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
🏷️ Discussion Type
Question
Title
Question about unreachable commits in private repositories
Body
Hi,
I have a general question about GitHub's handling of unreachable commits in private repositories.
If an unreachable commit contains sensitive data, what is the usual process for having it removed from GitHub?
In particular:
Thanks.
Guidelines
All reactions