GitHub Secret Leak Monitoring: Forks copy the original repo history, and after a BFG push, forks still keep the old secrets. Checks: 1) GitHub Insights → Network (shows the fork graph, tells us who forked it), 2) we don't have direct access to modify forks, but we can send DMCA notices to owners (GitHub abuse@github.com), 3) Secret scanning: GitHub Advanced Security (enable secret scanning → alerts on public repos), 4) Third-party monitoring (GitGuardian: email alerts if a password appears on public GitHub), 5) Database password change (even if old secrets are in forks, there's no access issue as long as the current password is new). After mitigation: 1) Clean history with BFG in the original repo, force push, 2) message fork owners (low chance of a reply), 3) report to GitHub abuse (forks are often abandoned — no cleanup support), 4) Rotate secrets (database, API keys, tokens). Proactive prevention: 1) .gitignore (exclude secrets), 2) GitHub secret scanning + protection rules (block commits with secrets), 3) pre-commit hooks (local scanning), 4) Start with a private repo, make it public only when free of secrets. Risk assessment: if the old secrets in forks aren't used (rotated), immediate risk is low (historical value), but security posture looks poor.