GitHub push protection blocked commit containing secret"
Clears a 'GitHub push protection blocked commit containing secret' block: remove the secret properly instead of bypassing. Use when GitHub blocks a push with this message. Not for local gitleaks blocks.
TL;DR
GitHub blocked the push because a commit contains a secret. The correct response is to remove the secret from the commit and push again, not to bypass the block. Bypass exists for true false positives and needs the right permission.
Error
"GitHub push protection blocked commit containing secret"Steps
- Read the block message for the secret type and location. Expected: file path and the kind of credential detected.
- Decide real or false positive by inspecting the flagged content. Expected: a clear verdict before you touch anything.
- If real, strip the secret from the commit (amend or rewrite), and rotate the credential if it was ever pushed anywhere. Expected: clean history and a dead credential.
- If it is genuinely a false positive (a test fixture, a documented example), add it to the repo's push-protection bypass list or request a bypass from someone with permission. Expected: the bypass is recorded and scoped.
- Push again and confirm the block is gone. Expected: successful push.
When to use
- The GitHub UI or git output shows the push-protection block message.
- You need the sanctioned path for true false positives.
When not to use
- The block comes from a local pre-commit hook (fix it locally).
- You are tempted to bypass a real secret to save time (rotate and remove instead).
Tool compatibility
- GitHub push protection on public and private repos.
Variant phrasings
push protection detected a secret in your commit
Same block.
bypass push protection for a false positive
The sanctioned escape hatch, not the default.
Why it happens
Push protection is a server-side scan on push. It knows provider-specific formats, so it catches things local regex scanners miss.
Edge cases
- Bypass permissions are per-organization; contributors cannot self-approve.
- Bypasses are logged; repeated bypasses of the same pattern should become an allowlist entry.
- If the secret was pushed to any other remote or fork, assume exposure and rotate.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_ok7AjPS2rMktFgNMrogAjg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.