5 ms·
Fun fact: there's a reflog on the GitHub remote so even if you force push you can still see what the previous commits in the repo were. So in this case even if
by nstj 8y ago
Fun fact: there's a reflog on the GitHub remote so even if you force push you can still see what the previous commits in the repo were.
So in this case even if you force push to the highly starred repo people could see that it had old commits (and restore to those on their local too).
Nice writeup on it: https://medium.com/git-tips/githubs-reflog-a9ff21ff765f https://medium.com/git-tips/githubs-reflog-a9ff21ff765f
This has definitely saved my bacon when I've force pushed to a GH repo before and had to restore something.
- saagarjha 8y agoHuh, I didn't think that GitHub kept a reflog. Although, after thinking about it, I guess that they really need to since links to old commits continue working…
- OJFord 8y agoI've only ever had them 404, which is why I assumed it didn't. Weird that we've had different experiences there.
- rococode 8y agoI'm no git master and after searching around a bit I wasn't able to find a clear answer to this so I'm hoping someone can enlighten me: Say I accidentally push some private info and overwrite the commit with a force push. The commit history doesn't show the mistake commit at all, but is it actually still accessible through reflog? I'm pretty sure I've done this with some of my smaller projects so now I'm concerned that some of my passwords/keys are actually floating around somewhere. I read some info about reflog automatically pruning, is it likely that this is the case for my projects and I have nothing to worry about?
- bjz_ 8y agoAfaik (I'm no security expert), as soon as you pushed them to a public repo you should change them all regardless of force pushing, because there's no way to take it back. Folks do trawl github for passwords and secrets.
- icebraining 8y agoGithub might have pruning, but you can't rely on it, since their Git management system is quite custom. That said, if the request for the Events (as shown in the previous link) doesn't show the problematic commit - or a commit that extends it -, I don't think anyone could fetch it without previously knowing the ID, and if they do, it's probably because they already have a local copy.
- nstj 8y agoYep you can recover from force pushes on the remote - ie: you can reset it. You have to do it using GitHub’s web API but it is possible (and handy!) As GitHub themselves say: > Warning: Once you have pushed a commit to GitHub, you should consider any data it contains to be compromised. If you committed a password, change it! If you committed a key, generate a new one [0] [0]: https://help.github.com/articles/removing-sensitive-data-from-a-repository/ https://help.github.com/articles/removing-sensitive-data-fro...