Secrets in source control have a long memory
Deleting a password from a file does not remove it from the repository. It remains in the history, permanently, and anybody who can read the code can read it.
This surprises people constantly. The fix is not a commit that tidies it up; the secret has to be treated as compromised and replaced, because there is no way to know who cloned the repository in the meantime. Rewriting history is possible, awkward, and does nothing about the copies already taken.
More on Passwords and secrets
- Password length beats decorative complexityAdd wheels, not squiggles
- Forced rotation can create predictable passwordsOnly one character moves
- Salts make identical passwords look differentOne grain each
- Every secret copy creates another secret to protectEvery copy needs its own guard
- Environment variables are not secret vaultsA label on the outside of the bag
- Temporary credentials shrink the theft windowSame theft, different window
