Vovy rotates the leaked key first, then scrubs it from your Git history, blocks .env files, and turns on push protection so it cannot happen again.
I accidentally committed my .env with my Stripe key to GitHub, fix it
How it works
- Find every leaked secret: Vovy scans the repo history and GitHub's secret scanning alerts to list every key exposed and which commit it landed in.
- Rotate the keys first: Vovy opens each provider's dashboard, like Stripe's API keys page, and rolls the key. Deleting the file does not help; bots scrape GitHub for keys within minutes.
- Update the new keys: Vovy puts the new keys in your local .env and your host's environment variables, then redeploys so nothing breaks.
- Scrub the history: Vovy uses git filter-repo to remove the file from every commit and force-pushes. This rewrites history, so it asks first.
- Prevent a repeat: Vovy adds .env to .gitignore, turns on push protection in Settings, and shows a card of every key rotated.
What you provide
- Access to the repo and each provider
- Your OK to rotate keys and rewrite history
What you get
- Every leaked key rotated
- Production updated with new keys
- Secrets removed from history
- Push protection turned on
FAQ
If I delete the file, am I safe?
No. The key is still in your Git history and may already be copied. Rotating the key is the step that protects you.
Is my repo private, so it doesn't matter?
Private lowers the risk but anyone with access, or any tool you connected, can still read it. Rotate anyway.
Will rewriting history break collaborators?
Yes, they need to re-clone or reset. For a solo repo it is painless. GitHub may keep cached views, so rotation still matters most.
Related tasks
All tasks