Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They key part is "Warning: Once you have pushed a commit to GitHub, you should consider any data it contains to be compromised. If you committed a password, change it! If you committed a key, generate a new one."

Removing the secrets from the repository is nice to have, but not that necessary - what is mandatory is to ensure that the compromised secrets are no longer useful, since they aren't secret any more and won't be ever again.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: