A token was committed, noticed the next day, and removed in a follow-up commit — the working tree is clean and `git log` shows a commit titled "Move the token to an environment variable." Is this incident closed? Walk through what you'd actually do.
No — removing a secret from the current working tree does not remove it from history. git log -p -S '<the token>' finds the exact commit that introduced it in seconds, and that history is sitting in every clone, every fork, every CI cache and every backup that was made before the fix. This is exactly what automated bots scanning public repositories do, often within minutes of a push. The only action that actually neutralises the exposure is rotating the token — making the old value invalid — because there's no way to "recall" every clone that already has it. Rewriting history afterward (git filter-repo, BFG) is worth doing to stop it spreading further, but it's cleanup, not remediation; it happens after the token is already rotated, not instead of it.