Blog
Home

Tagged “security”

← All articles
Letting Claude Code push its own branch to GitHub

25 September 2026

In my Claude Code container for new projects, the repos live on GitHub and there are no secrets in their history. So there, Claude creates its own feature branch off master and pushes it, and I review and approve the pull request. The setup is the GitHub CLI in the image, git using it for credentials, and a fine-grained token that lives outside the image.

Getting Claude Code's commits out of the container with a fetch-only remote

25 September 2026

Claude Code works in a history-free copy of my brownfield repo, because the real repo still has old credentials in its history. Getting its commits back used to mean a temporary remote and a manual push every time. Now the real repo has a permanent, fetch-only remote pointing at Claude's copy: I fetch, branch off master and cherry-pick, and nothing ever flows back into the container.

Erasing credentials from git history: the third option

23 September 2026

My last post covered copying a brownfield project into a clean repo and cherry-picking real commits back, dodging the secret rather than dealing with it. There's a more direct third option: rewrite history and remove the secret from the repo itself with git filter-repo. Here's how, what it costs, and why I still rotate the credential anyway.