---
title: "Git History Secrets | ShipSafe"
description: "Find secrets that were committed and later deleted but still live in your repo&#x27;s git history, recoverable by anyone who clones it."
doc_version: 2026-10-05
last_updated: 2026-10-05T15:58:55.253Z
canonical: https://ship-safe.co/docs/git-history-scanning
---

# Git History Secrets | ShipSafe

● Git History Secrets

# Deleting a secret isn't enough.

You committed an API key, noticed, and deleted it in the next commit. The key is gone from your files, so a normal scan sees nothing. But it is still sitting in your git history, and anyone who clones the repo can recover it. This scan walks your commit history and finds those secrets.

## What it does

ShipSafe reads the file versions touched by each commit and runs its secret detection across them, then flags the dangerous case: a secret that is **gone from your current files but still in history**. Those are the ones to act on first.

## Run it from your editor (MCP)

AGENT

Copy

```text
shipsafe_scan_history
  path: "."          # your local git repo
  maxCommits: 100    # how far back to look
```

HEADS UP· Found one? Two steps, in order

First, **rotate the credential** — assume it is compromised, because the repo is cloneable. Second, **purge it from history** with a tool like git filter-repo or BFG. Deleting the file in a new commit does not remove it from history.

The scan is read-only and fully local. It reads past file versions with git and never writes, pushes, or transmits your history anywhere.

[← PreviousLive App Probing (DAST)](https://ship-safe.co/docs/dast-scanning)[Next →Configuration](https://ship-safe.co/docs/configuration)

## Sitemap

Every page of this site, in markdown: [https://ship-safe.co/sitemap.md](https://ship-safe.co/sitemap.md)
