## TL;DR

GitHub blocked the push because a commit contains a secret. The correct response is to remove the secret from the commit and push again, not to bypass the block. Bypass exists for true false positives and needs the right permission.

## Error

```text
"GitHub push protection blocked commit containing secret"
```

## Steps

1. Read the block message for the secret type and location. Expected: file path and the kind of credential detected.
2. Decide real or false positive by inspecting the flagged content. Expected: a clear verdict before you touch anything.
3. If real, strip the secret from the commit (amend or rewrite), and rotate the credential if it was ever pushed anywhere. Expected: clean history and a dead credential.
4. If it is genuinely a false positive (a test fixture, a documented example), add it to the repo's push-protection bypass list or request a bypass from someone with permission. Expected: the bypass is recorded and scoped.
5. Push again and confirm the block is gone. Expected: successful push.

## When to use

- The GitHub UI or git output shows the push-protection block message.
- You need the sanctioned path for true false positives.

## When not to use

- The block comes from a local pre-commit hook (fix it locally).
- You are tempted to bypass a real secret to save time (rotate and remove instead).

## Tool compatibility

- GitHub push protection on public and private repos.

## Variant phrasings

### push protection detected a secret in your commit

Same block.

### bypass push protection for a false positive

The sanctioned escape hatch, not the default.

## Why it happens

Push protection is a server-side scan on push. It knows provider-specific formats, so it catches things local regex scanners miss.

## Edge cases

- Bypass permissions are per-organization; contributors cannot self-approve.
- Bypasses are logged; repeated bypasses of the same pattern should become an allowlist entry.
- If the secret was pushed to any other remote or fork, assume exposure and rotate.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_ok7AjPS2rMktFgNMrogAjg
