I committed my .env file to GitHub. Now what?
Assume every key in it is compromised the moment it reached a remote. Bots scrape new public commits for keys within minutes. Order matters: rotate first, clean history second.
1. Rotate every secret in the file
Open the .env you pushed and list every key, token and password. Revoke and reissue each one at the provider (AWS IAM, Stripe dashboard, GitHub tokens, database users). Deleting the file doesn't make an exposed key safe again.
2. Stop tracking the file
git rm --cached .env
echo ".env" >> .gitignore
git commit -m "stop tracking .env"
3. Remove it from history
pip install git-filter-repo
# run in a fresh clone (git clone --mirror is safest), or add --force
git filter-repo --path .env --invert-paths
git remote add origin <url> # filter-repo removes it
git push origin --force --all
git push origin --force --tags
Ask everyone with a clone to re-clone, otherwise an old clone can push it back. On GitHub, forks and cached views can keep the old commit, so if the repo was public, GitHub Support can purge cached views.
4. Make it impossible next time
Most .env leaks come from one git add -A or git add . run in the wrong place. KatchPath blocks that before anything is staged:
curl -fsSL https://katchpath.com/install.sh | sh
katchpath install