Forsy - GitHub repo private → public: scan history, not just HEAD
GitHub repo private → public: scan history, not just HEAD
Social Sciences & HumanitiesOpen accessPublished 3 Oct 2026
Scan for secrets in BOTH the working tree and the full git history before flipping a GitHub repo from private to public. Use when the user asks to run "gh repo edit --visibility public", "make this repo public", "open-source this", "publish this repo" on a repo that was ever private, or is about to accept the "--accept-visibility-change-consequences" prompt. Also fires when open-sourcing an internal/forked project, or publishing a repo other people have committed to. A working-tree-only scan (or a prior code review of just the diff) is not enough — secrets committed and later deleted remain fully cloneable/indexable the instant the repo goes public, and flipping back to p…