A 400 MB file is in the history. Removing it from HEAD did not shrink the repo.
It cannot: the object still lives in history. git filter-repo --strip-blobs-bigger-than 10M rewrites it out, after which everyone must reclone. Add the pattern to .gitignore in the same change, otherwise it comes back in a week.
What is the practical way to stop credentials landing in commits?
Two layers: a pre-commit hook that scans staged content, and push protection on the hosting side as a backstop. Neither is sufficient alone, because hooks are skipped with --no-verify and server-side scanning only sees what already left your machine.
What would you skip entirely?
The reporting layer, until something forces it. It is the part that feels productive to build and the part nobody opens twice.