Repository navigation
security: remove leaked database credentials and purge them from history - #90
Open
arnoldcastro5000 wants to merge 1 commit into
Open
arnoldcastro5000 wants to merge 1 commit into
arnoldcastro5000 wants to merge 1 commit into
Conversation
arnoldcastro5000
force-pushed
the
security/remove-db-credentials
branch
from
September 11, 2026 14:25
daa2100 to
10ee1df
Compare
arnoldcastro5000
marked this pull request as ready for review
September 11, 2026 14:27
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR does
This PR deletes the file
database/database.json.zaven. The file holds PostgreSQL database credentials in plain text. The credentials are public in this repository, so we must remove them.This PR is step 1 of 2. It removes the secret from the current branch. It does not remove the secret from the git history. A maintainer with admin rights must do step 2. The commands are below. You can copy and paste them.
Why
The file exposes the database user names, the host, and the passwords for three environments. A public repository shows this file to everyone. We treat every exposed credential as compromised.
The credentials are already rotated. The old values no longer work. This PR and the history purge remove the dead values from GitHub.
What changed here
database/database.json.zaven.This file is safe to delete. Nothing references it. It is a stray per-developer
db-migrateconfig, committed by accident with real credentials. No code, script, or CI job readsdatabase.json.zaven.The application and the migrations already read the database connection from environment variables.
knexfile.jsusesprocess.env.DATABASE_URL_SEEDER, and the.env*.examplefiles documentDATABASE_URL.db-migratereadsdatabase/database.json, which is not committed (onlydatabase.json.exampleis). So no runtime path depends on the deleted file.Step 2 — history purge (maintainer with admin only)
The old commit stays in the history after a normal delete. The secret sits in one commit (
e10c6de). It is also pinned by 58 tags (v1.8.0tov1.15.0) and by 5 other branches. You must rewrite the history and force-push.Requirements on your machine:
git(2.24 or newer),python3, andcurl. You do not need to installgit-filter-repo; Block 1 downloads it.Run the blocks in order, in one terminal session.
Block 1 — rewrite and verify locally (safe; does not push)
Manual gate A — lift branch protection
Lift the branch protection on
mainin the GitHub UI (Settings → Branches), or with your admin token. Record the current rules first, so you can restore them. A protected branch rejects the force-push.Block 2 — push the rewrite
Manual gate B — restore branch protection
Restore the branch protection on
mainwith the same rules you recorded in gate A.Block 3 — verify on a fresh clone (done-bar)
Two verification traps to avoid:
git clone --mirrorto verify. It fetches therefs/pull/*refs, which you cannot change, so it always shows the secret and reports a false failure.ondigitalocean.com. That string also appears in the.env*.exampleanddatabase.json.examplefiles, so it gives a false failure. Verify by file path, as shown.There are no open pull requests to close. Note: about 32 closed pull requests still keep a
refs/pull/N/headcopy of the secret. You cannot delete these refs; GitHub Support removes them in step 3. After the push, tell contributors to re-clone or rungit reset --hard, because the commit IDs have changed.Step 3 — residual exposure (maintainer with admin only; manual)
GitHub keeps old commits alive in three places you cannot reach with a push: the
refs/pull/*refs (about 32 closed pull requests), the cached commit views, and the ~11 forks. The values are dead, but do the best-effort cleanup:refs/pull/*/headcopies of the secret, to purge the cached commit views, and to remove the dangling commit from the shared fork-network storage.Scope