Tell users to rewrite Git history in GitGuardian message
What does this MR do and why?
The GitGuardian scan for Secret Push Protection runs pre-receive, so
by the time a developer sees the rejection, the commit containing the
secret is already part of their local Git history. The old
remediation message told them to "fix the violation" and "commit and
try pushing again," which implies stacking a new commit is enough.
It is not: the secret remains in a reachable commit and gets re-detected, and even after editing the file, that earlier commit can still leak the secret later through force pushes, mirrors, or backups. The message now tells developers to rewrite history and links to the "Remove a secret from your commits" tutorial. This also matches the docs-link convention the native Secret Push Protection check already follows.
REMEDIATION_MESSAGE is now a format template with a %{path}
placeholder so the help URL is resolved at call time.
References
- Closes #620772 (closed)
Screenshots or screen recordings
❯ git push
Enumerating objects: 5, done.
Counting objects: 100% (5/5), done.
Delta compression using up to 16 threads
Compressing objects: 100% (2/2), done.
Writing objects: 100% (3/3), 309 bytes | 309.00 KiB/s, done.
Total 3 (delta 1), reused 0 (delta 0), pack-reused 0 (from 0)
remote: GitLab: .env: 1 incident detected:
remote:
remote: >> Secrets detection: Generic Password
remote: Validity: No checker
remote: Known by GitGuardian: No
remote: Incident URL: N/A
remote: Violation: password `124gvb235asdq24vv12` detected
remote: 1 | PASSWORD=124gvb235asdq24vv12
remote: |____password_____|
remote:
remote: How to remediate:
remote:
remote: Since the secret was detected after the commit but before the push, you need to:
remote:
remote: 1. Rewrite the Git history, making sure to remove the secret(s).
remote: 2. Push again.
remote:
remote: For guidance, see http://gdk.test:3000/help/user/application_security/secret_detection/remove_secrets_tutorial.md#remove-the-secret-from-the-history
remote:
remote: [To apply with caution] If you want to bypass the secrets check:
remote:
remote: 1. Add [skip secret push protection] flag to the commit message or add the following Git push option: `-o secret_push_protection.skip_all`.
remote: 2. Commit and try pushing again.
To ssh://gdk.test:2222/flightjs/Flight.git
! [remote rejected] master -> master (pre-receive hook declined)
error: failed to push some refs to 'ssh://gdk.test:2222/flightjs/Flight.git'
How to set up and validate locally
- In the GDK, setup the Git Guardian integration on a project.
- In a local clone, make a change that includes a password eg. create an
.envfile and includePASSWORD=124gvb235asdq24vv12 - Push the changes, you should see the new remediation message with the doc link.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.