security1 publisher
GitHub's guidance on leaked secrets puts rotation ahead of rewriting history
GitHub's page on removing sensitive data tells teams to revoke and rotate first, and says the extra work of rewriting history often is not warranted when clones, forks and cached SHA-1 views keep the old commit anyway.
Publishers:docs.github.com
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−10
- Incentives60
- Confidence70