Keeping secrets out of a repository

Back to list2026-08-18
You

What is the practical way to stop credentials landing in commits?

ChatGPT

Two layers: a pre-commit hook that scans staged content, and push protection on the hosting side as a backstop. Neither is sufficient alone, because hooks are skipped with --no-verify and server-side scanning only sees what already left your machine.

You

I need one commit from a long branch, not the rest.

ChatGPT

git cherry-pick <sha> is the direct answer, but check whether the commit depends on earlier ones first. If it does, the conflict you get is real information: the change was never independent, and copying it alone will compile but misbehave.

You

Does commit signing matter for a solo public project?

ChatGPT

It proves commits came from a key you control, which matters mostly for released tags and for actions others automate against. For everyday commits on a one-person project it is largely ceremony, and an expired key causes more confusion than it prevents.