Dev Overflow Logo

Dev Overflow

Global search

Search across questions, answers, users and tags.

Git: how do I undo a commit I already pushed?

clock icon

asked 1 month ago

message icon

2

eye icon

2.1K

I pushed a commit to main with a hardcoded API key. I know I have to rotate the key, but what is the right way to get the commit out of history when other people have already pulled?

2 Answers

Rotate the key first — treat it as leaked the moment it was pushed. Everything below is cleanup, not remediation.

For a shared branch, prefer a forward fix:

1git revert <sha>
2git push
1git revert <sha>
2git push

This adds a new commit undoing the change and breaks nobody's history. The secret is still in the old commit, which is why rotation is not optional.

If the history genuinely must be scrubbed (compliance, public repo), rewrite and coordinate:

1git filter-repo --path config/secrets.json --invert-paths
2git push --force-with-lease
1git filter-repo --path config/secrets.json --invert-paths
2git push --force-with-lease

Then every collaborator re-clones. Use --force-with-lease rather than --force so you don't clobber someone's push that landed while you were rewriting.

And add a pre-commit secret scanner afterwards. Rotating once is fine; rotating monthly because the same mistake keeps happening is a process problem, not a git problem.

1

of 1

Write your answer here

Introduce the problem and expand on what you've put in the title.

Top Questions