Rewriting history
Rewriting commits, removing large files or sensitive data from history, and what it does to the commits tracing maps point to.
Your repository lives in your GitHub account, so its history is yours to rewrite: OSCR neither blocks nor reverses it. A rewrite gives new ids to the changed commit and to every commit after it. A tracing map points to one commit by its id: read what it does to tracing maps before you rewrite commits a paper cites.
Rewriting commits
The last commit, not yet pushed, is amended. Older ones are reworded, squashed or dropped with an interactive rebase. Once pushed, a rewrite needs a forced push; --force-with-lease refuses it when someone else has pushed since you fetched. A ruleset or a branch protection may refuse forced pushes to the branch.
git commit --amend -m "A better message" git push --force-with-lease origin main
git rebase -i HEAD~3 git push --force-with-lease origin main
Sources: Changing a commit message,git rebase.
Removing large files from history
GitHub refuses a push with a file over 100 MiB, even when a later commit deletes it: the file is still in the history the push sends. When the file came in the last commit, remove it from that commit:
git rm --cached data/recordings.h5 echo "data/recordings.h5" >> .gitignore git add .gitignore git commit --amend -C HEAD git push
When it came in an older commit, rewrite the history with git filter-repo, in a fresh mirror clone, then put the file where large files go (large files):
git clone --mirror https://github.com/OWNER/NAME.git cd NAME.git git filter-repo --path data/recordings.h5 --invert-paths git push --force --mirror origin
Sources: About large files on GitHub,git filter-repo.
Removing sensitive data from history
- Revoke the secret first. A token, a key or a password that was pushed is exposed, whatever the history says next: revoke it where it was made (a GitHub token: delete it), and make a new one.
- Rewrite the history with
git filter-repo --sensitive-data-removal: remove the file, or replace the text in every commit (one expression per line in a file kept outside the repository). - Force-push every branch and tag.
- Ask GitHub Support to remove the cached views and the pull request references that still hold the old commits: GitHub's page gives the steps and what to send.
- Every clone, yours and your collaborators', is replaced by a fresh clone, or reset:
git filter-repo --sensitive-data-removal --invert-paths --path config/credentials.json git filter-repo --sensitive-data-removal --replace-text ../expressions.txt git push --force --mirror origin
git fetch origin git reset --hard origin/main
Personal data in a repository, a participant's details for example, is removed the same way. Sources:Removing sensitive data from a repository,git filter-repo.
What it does to tracing maps
A tracing map joins a paper's paragraphs to lines of code at one commit. When a rewrite, or the deletion of the repository, takes that commit away from GitHub:
- The map stays, and the paper's page shows the commit as no longer at the source, in words, with the script copies OSCR keeps where the repository's licence allows it.
- Commits before the rewritten one keep their ids: a map pointing to them is untouched. Tag the commit a paper cites (tags) and rewrite after it when you can.
- To keep the cited commits readable whatever happens to the repository, ask for them to be archived by Software Heritage when you validate a map. OSCR sends that request only when you ask for it, never by default.
- A map for the new history is a new map, which an author validates again; the old one stays citable with its own commit.
Asking OSCR to drop its own copies
Rewriting your history does not change what OSCR already copied: the record of the paper, its tracing maps and, when the licence allowed it, the scripts' text. When something there must go (personal data, a secret, a copyright question, an author's request), request its removal from the paper's page: its sidebar's "Request its removal", or the removal section under Contribute, signed in. You say the reason in a few words; OSCR's owner decides, and the answer is written on your account page. Accepted, the record leaves every public output of OSCR at the next nightly update: the site, the lookup, the search and the open data.
Revoke an exposed secret yourself first: a removal request takes days, a revocation a minute.
