How can a GitHub Standard account request server-side cleanup after a sensitive-data history rewrite? #209921
Replies: 2 comments
|
You don’t need a paid plan to get this handled. The “Technical support not included” label covers general how-to help. A sensitive-data removal request is a different thing, and GitHub treats it as one. Where to file it. Go to support.github.com/contact while signed in to the owner account. If no category matches exactly, pick the closest one under account or security and say at the top of the first message: “This is a sensitive-data removal request per the GitHub Docs page, not a technical support question.” That one sentence helps the ticket get routed to the right team instead of getting a canned reply. What to put in the ticket. You already have the right material, so write it up in this order: The repository’s full name (owner/repo) Keeping it private. The ticket is the private channel. Nothing in it is public, so put the repo name and hashes there and nowhere else. If you want a GitHub staff member to see this thread, tell them in the post that you filed a ticket and share the ticket number only. Staff can use that to find it and push it along without any identifiers appearing here. If the form blocks you. Reply to the confirmation email thread once a day or so rather than opening duplicates, since duplicates slow things down. Also keep the rewrite itself done: don’t delete the repo, because Support can run the cleanup on the existing one. One last point: the removal on GitHub’s side won’t touch copies in anyone’s local clones, so the credential rotation is still your real protection. |
|
hey, don't worry—github actually does provide support for sensitive data removal and security issues on free/standard accounts, even though it says "technical support not included" for general stuff. security and account issues bypass that restriction. here’s how you can get your ticket submitted privately without having to delete the repo: use the right support category: go to the github support portal, but instead of looking for general repo help, you need to select the category for account, security, and abuse issues. this queue is open to everyone regardless of their billing plan. try the direct link: if the portal keeps looping you back to the "no support" page, try using the direct request form at what to include: in your private ticket, you'll need to give them exactly what you already prepared. provide your repo name, the affected pull request count, the "first changed commit" output from git-filter-repo, and any orphaned lfs objects. just drop all that info into the security ticket and they'll run the server-side garbage collection and clear the cached views for you. it might take a little bit for them to respond, but they'll get it done! |
Uh oh!
There was an error while loading. Please reload this page.
🏷️ Discussion Type
Question
Body
Title: How can a GitHub Standard account request server-side cleanup after a sensitive-data history rewrite?
Hello GitHub Community,
I own a private GitHub repository and have completed a sensitive-data history rewrite using
git-filter-repo2.47.0.All affected branches and tags have been updated, and the repository is functioning normally. However, historical commits remain accessible through their original SHA references.
GitHub's documentation, Removing sensitive data from a repository, instructs repository owners to contact GitHub Support for server-side garbage collection and cached-view removal.
My Personal / Standard account displays “Technical support not included,” and the available support ticket categories do not appear to cover this request.
Could GitHub staff advise how I can privately submit the required evidence and request server-side cleanup without deleting the repository?
I have prepared the affected pull-request count, First Changed Commit, fork status, and LFS findings.
For privacy reasons, I prefer not to disclose repository identifiers or historical commit hashes publicly.
Thank you.
All reactions