forumNew topic

Could someone have forked my public repo on GitHub and found the secrets? How can I check?

İİbrahim T***MemberCommunity member
Joined
Aug 2023
Message
279
#1

There used to be a password in my public repo (in the history). If someone forked it, they can see it in the history. Can I check these forks? Can I get notifications?

I already cleaned the history on GitHub (BFG), but forks keep the old code. I'm afraid the password is still at risk.

How can I minimize the risk of secrets leaking when opening a public repo from now on?

CCihanMember
Job title
Credit Consultant
Joined
Jun 2024
Message
92
Most Helpful#2

GitHub Secret Leak Monitoring: Forks copy the original repo history, and after a BFG push, forks still keep the old secrets. Checks: 1) GitHub Insights → Network (shows the fork graph, tells us who forked it), 2) we don't have direct access to modify forks, but we can send DMCA notices to owners (GitHub abuse@github.com), 3) Secret scanning: GitHub Advanced Security (enable secret scanning → alerts on public repos), 4) Third-party monitoring (GitGuardian: email alerts if a password appears on public GitHub), 5) Database password change (even if old secrets are in forks, there's no access issue as long as the current password is new). After mitigation: 1) Clean history with BFG in the original repo, force push, 2) message fork owners (low chance of a reply), 3) report to GitHub abuse (forks are often abandoned — no cleanup support), 4) Rotate secrets (database, API keys, tokens). Proactive prevention: 1) .gitignore (exclude secrets), 2) GitHub secret scanning + protection rules (block commits with secrets), 3) pre-commit hooks (local scanning), 4) Start with a private repo, make it public only when free of secrets. Risk assessment: if the old secrets in forks aren't used (rotated), immediate risk is low (historical value), but security posture looks poor.

YYasemin T***New memberCommunity member
Joined
Aug 2026
Message
68
#3

check forks in the network tab. if there are old secrets change the database password anyway. you can send a dmca notice on github, checking private forkks isn't possible but turn on secret scanning on github to get alerts....

PPolat K***MemberCommunity member
Joined
May 2023
Message
329
#4

GitHub fork tracking: 1) REST API (curl https://api.github.com/repos/user/repo/forks → lists all forks, created_at timestamp), 2) Network graph (GitHub UI shows fork timeline + owner), 3) GitGuardian (monitors public GitHub, email alert if credentials are visible), 4) Dependency Check (OWASP: scans repo for known leaked data in dependencies). Secret scanning: GitHub Advanced Security (Enterprise/Pro) scans automatically, third-party TokenScan (monitors GitHub pushes). Notification: DMCA notice (GitHub sends removal request to fork owner), private message (lower success rate). Risk: old secrets in the fork + leak in the fork = attacker sees credentials, but if the original is rotated, access is denied (low immediate risk).

BBeyza T***MemberCommunity member
Joined
Nov 2024
Message
336
#5

Check forks they're listed in the network tab... Turn on secret scanning on GitHub. If you've rotated the password, the forks don't matter... Send a DMCA notice on GitHub but reaching fork owners is hard. In the future don't store anything sensitive in public repos at all...

HHazalMember
Job title
UX Researcher
Joined
May 2024
Message
118
#6

GitHub security best practices: 1) Repo settings (private by default, public only for mature projects), 2) Mandatory secret scanning (GitHub Advanced Security: blocks pushes containing secrets), 3) Branch protection (require review + passing checks), 4) Audit log (see who pushed what), 5) CODEOWNERS (assign code reviews). Fork security: a fork inherits the parent's history + secret scanning (if enabled), but the fork owner controls settings independently. Remediation transparency: publish a security advisory (GitHub security advisory), publish an incident report, document root cause + fixes.

AAslıMember
Job title
Product photographer
Organization type
early-stage startup
Joined
Jul 2024
Message
76
#7

Exactly, and not many people know this. When we decide without measuring, we always end up in the same place.

Proven by experience.

OOrhan D***New memberCommunity member
Joined
Jul 2026
Message
347
#8

There's a trap here, let me mention it. When we decide without measuring, we always end up in the same place.

Everything goes well for the first three months; problems arise in the fourth. Correct me if I'm wrong.

VVildan Y***Member
Job title
Content Editor
Sector
Retail
Organization type
20-person company
Joined
Nov 2024
Message
70
#9

I agree with this. The harder it is to reverse a decision the slower you should make it.

İİbrahim B***Member
Job title
Production planning
Sector
Livestock
Organization type
chain store
Joined
Feb 2024
Message
24

Doki · Log management setup · 2024

#10

Looking at it as a process, the picture changes. Taking notes for two weeks yields better results than a six-month estimate.

If you have questions, write them; I'll answer as best I can.

SSultan B***Member
Job title
Front office accounting
Sector
Security services
Organization type
8-person team
Joined
Feb 2025
Message
23
#11

There's a trap here, let me mention it. Start with a small trial; don't commit to everything at once.

That's all, sorry if I went on too long.

İİlker K***Expert
Job title
Software developer
Sector
Freight
Organization type
300-person organization
Joined
Nov 2022
Message
42
#12

Thanks for writing this, that's the right way. An automated scan report is not the same as a penetration test.

RRecep Y***Member
Job title
System administrator
Sector
Sports and fitness
Organization type
boutique agency
Joined
Jun 2022
Message
9
#13

I'll argue the opposite, don't get mad. Everything goes well for the first three months; problems arise in the fourth.

GGürkan K***MemberCommunity member
Joined
Sep 2025
Message
189
#14

You're right I've been down that road too. People defend habits, not processes. anyway resistance comes from there.

ZZeynep O***New member
Job title
Business Owner
Sector
Furniture manufacturing
Organization type
family business
Joined
May 2026
Message
1
#15

This thread is archived.

SSılaMember
Job title
Marketplace specialist
Organization type
8-person team
Joined
Mar 2024
Message
138
#16

I have a question, don't want to go off-topic though. Taking measures without an inventory leaves doors you haven't seen open.

I'm also curious if anyone does it differently.

KKader K***MemberCommunity member
Joined
Oct 2023
Message
6
#17

I completely agree. Everyone rushing into github leak gets stuck at the same point.

That's all, sorry if I went on too long.

ZZerrin Y***Member
Job title
Production Manager
Sector
Retail
Organization type
family business
Joined
Oct 2022
Message
11
#18

Thanks a lot, I'll try it today. Everything goes well for the first three months; problems arise in the fourth.

That's all, sorry if I went on too long.

DDamla Y***ExpertCommunity member
Joined
Feb 2025
Message
57
#19

I partly agree, partly disagree. Forgotten test environments are more often the entry point than live systems.

If permission and scope aren't in writing, don't start that test.

YYasinNew member
Job title
Technical Service
Joined
Nov 2024
Message
30
#20

Same here.

Reply