{"version":"2.1.280","anchor":"new-refusal-message-for-secretscredentials-committed-mid-up","canonical_anchor":"new-refusal-message-for-secretscredentials-committed-mid-up","heading":"New refusal message for secrets\/credentials committed mid-upload","tier":"notice","area":"Permissions","scope":null,"heads_up":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/new-refusal-message-for-secretscredentials-committed-mid-up","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### New refusal message for secrets\/credentials committed mid-upload\n\nClaude Code now refuses uploads when a secret or credential was committed partway through preparing them\n\n**Unclear.** The finding doesn't specify which upload feature or command this applies to, or how the detection is triggered.\n\n**What**\n\nIf Claude Code detects that a file containing secrets or credentials was committed while it was preparing an upload, it now shows a clear refusal message explaining the problem instead of proceeding. The message tells you to amend or reset the commit or commits that added the file, and it specifically warns that deleting the file in a later commit is not enough to fix the problem, since the secret would still exist in the commit history.\n\n**Why**\n\nThis helps prevent secrets and credentials from ending up in a commit history that gets uploaded, even if a fix attempt only removes the file in a newer commit. It pushes users toward properly rewriting the offending commits rather than leaving exposed data reachable through git history.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}