GitHub "push declined: secret detected" (GH013)
GitHub's push protection found a token in one of the commits you're pushing. The push is blocked, so the key hasn't gone public through this push. It's still sitting in your local commit, and removing it from the latest file isn't enough.
Fix the commit, not just the file
If it's in the last commit:
git rm --cached path/to/file # drop the file, or:
# edit the key out, then: git add path/to/file
git commit --amend
git push
If it's further back, rewrite from before that commit:
git rebase -i <commit-before-the-secret>
# mark the commit as "edit", remove the key, then:
git add path/to/file
git commit --amend && git rebase --continue
Should you rotate?
If the push was blocked and the key exists nowhere else, rotation is optional but cheap. If it was ever pushed anywhere (another remote, a fork, CI logs), rotate it.
Catch it before the push
Push protection only covers some token types, and only on GitHub. KatchPath checks at git add and commit time on your machine:
curl -fsSL https://katchpath.com/install.sh | sh