this post was submitted on 13 Nov 2025
90 points (98.9% liked)
Opensource
4308 readers
102 users here now
A community for discussion about open source software! Ask questions, share knowledge, share news, or post interesting stuff related to it!
⠀
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
If he pushed something he shouldn't have online then taking it offline immediately makes a lot of sense.
It makes sense, but once it's pushed there is no way to know if it's been cloned or kept somewhere else. The only real mitigation is to rotate the keys or password that was leaked.
If it's something else you can't rotate, you're screwed.
https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github
The point wasn't that it's not accessible but limiting the damage while you still can.