forumNew topic

if a database password was published in a github commit, i need to hide it quickly

YYağmur C***MemberCommunity member
Joined
May 2023
Message
274
#1

a dev committed to github, the included config file has the database password. it's visible in a public repo. what should i do immediately?

i changed the password in the database, but it's still visible in the github history. should i wipe the commit history?

can automated tools do secret detection? can i catch it beforehand?

ZZehra K***MemberCommunity member
Joined
Mar 2025
Message
86
Most Helpful#2

Secret Leak Incident Response: Quick response is critical. Steps: 1) IMMEDIATE (1-5 min): a) Change DB password, b) Revoke GitHub repo access (check collaborators), c) Enable GitHub secret scanning alert if available (Settings → Security → Secret scanning), 2) SHORT TERM (5-30 min): a) Clean git history (BFG Repo-Cleaner: bfg --delete-files 'config.yml' — rewrite history), b) Force push (git push --force-with-lease) — WARNING: Team coordination required, c) Check other repos (grep -r password *.git), 3) REVIEW (30-60 min): a) Check git log (who pushed, when), b) Access logs (DB): any suspicious login attempts?, c) Check AWS CloudTrail, GCP Cloud Audit Logs, 4) NOTIFICATION: a) Inform team (git rewrite warning, rebase needed), b) DB team (password rotation). Prevention tools: 1) .gitignore (exclude config files), 2) env vars (.env, git-ignored), 3) GitHub secret scanning (built-in + third-party: TruffleHog, GitGuardian), 4) commit hooks (pre-commit framework: detect secrets before commit), 5) automated scanning (CI/CD: scan commits for patterns). Risk mitigation: DB access logs (suspicious IPs, query patterns), API rate limiting (prevent brute force), DB MFA (if supported).

EEfe Y***Member
Job title
Site Manager
Sector
Leather
Organization type
boutique agency
Joined
Jul 2025
Message
367
#3

change the db password immediately. use bfg-repo-cleaner or git-filter-branch to wipe history on github. tell the team they need to git rebase. turn on secret scanning on github, bfg handles it automatically in the background.....

UUğur E***MemberCommunity member
Joined
Jan 2023
Message
17
#4

Secret remediation: 1) BFG Repo-Cleaner (bfg --replace-text passwords.txt --no-blob-protection repo.git), 2) git-filter-branch (legacy, slower but precise), 3) GitHub secret scanning + automatic revocation (auto-revoke if it's a token), 4) Audit: git log -S 'password' --all (search commits), 5) Notify: check if attackers accessed the database (query logs, failed login attempts, IP geolocation). Prevention implementation: pre-commit hook (pre-commit framework + plugins: detect-secrets, truffleHog), CI/CD scanning (GitHub Actions: Trivy, GitGuardian), .gitignore template (.env, *.key, config.local.yml). Team communication: git history rewrite requires all users to force-pull + rebase (coordination overhead).

BBurcu A***Member
Job title
Operations director
Sector
Cosmetics
Organization type
regional distributor
Joined
Jan 2022
Message
5

Doki · Mobile app · 2026

#5

change the password immediately use BFG to wipe history. warn the team about git rebase... btw enable secret scanning on GitHub. set up pre-commit hooks (truffleHog, detect-secrets) to catch this in the future. add CI/CD scanning...

HHakan U***MemberCommunity member
Joined
Apr 2024
Message
43
#6

Secret detection automation: 1) Local pre-commit (pre-commit framework + detect-secrets plugin), 2) CI/CD pipeline (GitHub Actions GitLab CI: TruffleHog GitGuardian), 3) Repo scanning (GitHub native secret scanning GitLab security scanning), 4) Git history audit (git-secrets, git-dumper). Response automation: GitHub secret scanning → auto-revoke (for GitHub tokens) alert team create incident log. Best practices: .gitignore template (exclude *.key, *.pem .env, config/*local*), env var strategy (all secrets in CI/CD env vars, never in code), secret management service (HashiCorp Vault, AWS Secrets Manager).

SSena G***MemberCommunity member
Joined
Feb 2023
Message
356
#7

I'm a small business, let me explain from my side. The real issue isn't the number but what it's based on.

Proven by experience.

FFatih G***Member
Job title
Production planning
Sector
IT services
Organization type
medium-sized business
Joined
Nov 2024
Message
31
#8

Thanks, this was very helpful. Forgotten test environments are more often the entry point than live systems.

That's all, sorry if I went on too long.

ÖÖmer D***Member
Job title
Field sales representative
Sector
Automotive aftermarket
Organization type
medium-sized business
Joined
Aug 2024
Message
341
#9

This thread is archived.

İİlker K***Member
Job title
Information Security Specialist
Sector
Glass
Organization type
a company within a holding
Joined
Jul 2025
Message
185
#10

Let's separate the concepts they're getting mixed up. If you scold false alarms, nobody will report again.

Correct me if I'm wrong.

NNecati T***Member
Job title
Chief Technology Officer
Sector
Healthcare services
Organization type
two-branch business
Joined
Nov 2025
Message
82

Doki · Brand identity · 2026

#11

Let me share what happened to me; it might be useful. Mistakes made on the password left in source code side are usually reversible but expensive.

Start with a small trial; don't commit to everything at once. That's all, sorry if I went on too long.

ÜÜlkü N***Member
Job title
Courier coordinator
Sector
Energy
Organization type
300-person organization
Joined
Mar 2024
Message
64
#12

I don't think this advice fits everyone. Most incidents start with a leaked password, not a vulnerability.

MMetin P***ExpertCommunity member
Joined
Jun 2023
Message
186
#13

it's rare to find an explanation this clear.

OOrhan T***MemberCommunity member
Joined
Mar 2024
Message
242
#14

Correct.

JJale P***MemberCommunity member
Joined
Mar 2024
Message
207
#15

We need to make a distinction here. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

If I were you, I'd go this route.

AAleyna K***New member
Job title
Quality control inspector
Sector
Livestock
Organization type
120-person company
Joined
Jun 2026
Message
1
#16

I'm a small business, let me explain from my side. Payment information changes are never verified through the channel they came from.

MMerve T***ExpertCommunity member
Joined
Feb 2024
Message
13
#17

Let me share what happened to me; it might be useful. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

People defend habits, not processes. Resistance comes from there. This is my opinion, I'm not claiming it's absolute truth.

SSultan Ö***Expert
Job title
Data entry clerk
Sector
Sports and fitness
Organization type
early-stage startup
Joined
Feb 2023
Message
10
#18

I agree.

BBeyza K***MemberCommunity member
Joined
Mar 2024
Message
337
#19

Thanks, this was very helpful.

CCem E***Member
Job title
Project manager
Sector
Law
Organization type
20-person company
Joined
May 2023
Message
213
#20

Looking at it as a process, the picture changes. Security isn't absolute; it's about making attacks not worth the effort.

Of course, it varies if your situation is different.

Reply