OSCR

Rewriting history

Rewriting commits, removing large files or sensitive data from history, and what it does to the commits tracing maps point to.

Your repository lives in your GitHub account, so its history is yours to rewrite: OSCR neither blocks nor reverses it. A rewrite gives new ids to the changed commit and to every commit after it. A tracing map points to one commit by its id: read what it does to tracing maps before you rewrite commits a paper cites.

Rewriting commits

The last commit, not yet pushed, is amended. Older ones are reworded, squashed or dropped with an interactive rebase. Once pushed, a rewrite needs a forced push; --force-with-lease refuses it when someone else has pushed since you fetched. A ruleset or a branch protection may refuse forced pushes to the branch.

git commit --amend -m "A better message"
git push --force-with-lease origin main
git rebase -i HEAD~3
git push --force-with-lease origin main

Sources: Changing a commit message,git rebase.

Removing large files from history

GitHub refuses a push with a file over 100 MiB, even when a later commit deletes it: the file is still in the history the push sends. When the file came in the last commit, remove it from that commit:

git rm --cached data/recordings.h5
echo "data/recordings.h5" >> .gitignore
git add .gitignore
git commit --amend -C HEAD
git push

When it came in an older commit, rewrite the history with git filter-repo, in a fresh mirror clone, then put the file where large files go (large files):

git clone --mirror https://github.com/OWNER/NAME.git
cd NAME.git
git filter-repo --path data/recordings.h5 --invert-paths
git push --force --mirror origin

Sources: About large files on GitHub,git filter-repo.

Removing sensitive data from history

  1. Revoke the secret first. A token, a key or a password that was pushed is exposed, whatever the history says next: revoke it where it was made (a GitHub token: delete it), and make a new one.
  2. Rewrite the history with git filter-repo --sensitive-data-removal: remove the file, or replace the text in every commit (one expression per line in a file kept outside the repository).
  3. Force-push every branch and tag.
  4. Ask GitHub Support to remove the cached views and the pull request references that still hold the old commits: GitHub's page gives the steps and what to send.
  5. Every clone, yours and your collaborators', is replaced by a fresh clone, or reset:
git filter-repo --sensitive-data-removal --invert-paths --path config/credentials.json
git filter-repo --sensitive-data-removal --replace-text ../expressions.txt
git push --force --mirror origin
git fetch origin
git reset --hard origin/main

Personal data in a repository, a participant's details for example, is removed the same way. Sources:Removing sensitive data from a repository,git filter-repo.

What it does to tracing maps

A tracing map joins a paper's paragraphs to lines of code at one commit. When a rewrite, or the deletion of the repository, takes that commit away from GitHub:

Asking OSCR to drop its own copies

Rewriting your history does not change what OSCR already copied: the record of the paper, its tracing maps and, when the licence allowed it, the scripts' text. When something there must go (personal data, a secret, a copyright question, an author's request), request its removal from the paper's page: its sidebar's "Request its removal", or the removal section under Contribute, signed in. You say the reason in a few words; OSCR's owner decides, and the answer is written on your account page. Accepted, the record leaves every public output of OSCR at the next nightly update: the site, the lookup, the search and the open data.

Revoke an exposed secret yourself first: a removal request takes days, a revocation a minute.

The hosting guides