惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
雷峰网
雷峰网
博客园 - 三生石上(FineUI控件)
月光博客
月光博客
有赞技术团队
有赞技术团队
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
G
Google Developers Blog
腾讯CDC
B
Blog
Microsoft Azure Blog
Microsoft Azure Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Microsoft Security Blog
Microsoft Security Blog
人人都是产品经理
人人都是产品经理
博客园_首页
T
Tailwind CSS Blog
C
Check Point Blog
博客园 - 【当耐特】
MongoDB | Blog
MongoDB | Blog
A
About on SuperTechFans
Y
Y Combinator Blog
L
LangChain Blog
Engineering at Meta
Engineering at Meta
GbyAI
GbyAI

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
Accidentally Pushed a `.env` Secret to a Public GitHub Re...
Kashaf Abdullah · 2026-06-19 · via DEV Community

Kashaf Abdullah

Exposing secrets in a public GitHub repository is a real production emergency. Public repositories are continuously scanned by automated bots, and leaked credentials can be discovered within minutes.

If this happens, act immediately.


1. Assess the Impact Immediately

Start by identifying exactly what was exposed.

Questions to ask:

  • Were API keys leaked?
  • Did database credentials appear in the repository?
  • Were cloud credentials exposed (AWS, GCP, Azure)?
  • Did payment gateway secrets become public?
  • Were JWT signing keys included?
  • Were admin or service tokens exposed?

The faster you understand the scope, the faster you can contain the issue.


2. Revoke and Rotate All Exposed Secrets

Deleting the file is not enough.

Assume any exposed credential has already been copied and rotate it immediately.

Generate new credentials for:

  • API keys
  • Database passwords
  • Access tokens
  • Cloud credentials
  • Authentication secrets
  • Webhook secrets

After rotation, update all environments and redeploy applications so production stops using old credentials.


3. Remove Secrets from Git History

Removing the .env file in a new commit does not erase it from earlier commits.

Clean repository history using tools such as:

  • git filter-repo
  • BFG Repo Cleaner

Once cleaned:

  • Force-push the updated history
  • Ask collaborators to re-clone or reset local repositories if necessary

Remember: history cleanup improves hygiene, but secret rotation is the actual remediation.


4. Investigate for Suspicious Activity

Review logs to determine whether exposed credentials were abused.

Check:

  • Cloud audit logs
  • Database access history
  • API request logs
  • Authentication events
  • Billing and usage anomalies

Look for unusual activity after the exposure timestamp.


5. Notify the Team and Stakeholders

Security incidents should be communicated clearly.

Inform relevant stakeholders such as:

  • Engineering teams
  • Security teams
  • Project owners
  • Management (if required)

Document:

  • What happened
  • What was exposed
  • Actions taken
  • Current status

Transparency helps teams respond faster and improve future processes.


6. Prevent It from Happening Again

Once the incident is resolved, strengthen your workflow.

Recommended safeguards:

  • Enable GitHub Secret Scanning
  • Add .env files to .gitignore
  • Use pre-commit secret detection
  • Add CI/CD security checks
  • Store secrets in dedicated secret managers
  • Follow least-privilege access principles

The goal isn't only fixing the leak — it's making sure the next one never happens.


Quick Checklist

Step Action Status
1 Assess the impact
2 Revoke and rotate secrets
3 Remove secrets from Git history
4 Investigate for suspicious activity
5 Notify team and stakeholders
6 Prevent it from happening again


Final Thought

Secret exposure incidents happen even to experienced teams. What matters most is how quickly you detect, rotate, contain, and improve your process afterward.


Written by Kashaf Abdullah

Software Engineer | MERN Stack | Web Development


Found this helpful? Leave a ❤️ and bookmark it for later!

Let's discuss in the comments: Have you ever accidentally leaked secrets? What steps did you take?