You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.280,
ImprovementsSection of the release
What
If Claude Code detects that a file containing secrets or credentials was committed while it was preparing an upload, it now shows a clear refusal message explaining the problem instead of proceeding. The message tells you to amend or reset the commit or commits that added the file, and it specifically warns that deleting the file in a later commit is not enough to fix the problem, since the secret would still exist in the commit history.
Why
This helps prevent secrets and credentials from ending up in a commit history that gets uploaded, even if a fix attempt only removes the file in a newer commit. It pushes users toward properly rewriting the offending commits rather than leaving exposed data reachable through git history.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe finding doesn't specify which upload feature or command this applies to, or how the detection is triggered.