

Plus won’t the forks on GitHub keep the history before the “reset”?
Afaik, forks on GitHub are basically the same underlying repository, just a branch associated with another user. They won’t be able to really purge anything from these other branches.
Plus anyone who has a local copy of the repo or an automatic mirror somewhere else, will have the changes available.










It makes sense, but once it’s pushed there is no way to know if it’s been cloned or kept somewhere else. The only real mitigation is to rotate the keys or password that was leaked.
If it’s something else you can’t rotate, you’re screwed.