[All work](https://boiko.ai/work/)

Developer security · Repository release

# go-public

Audit a private repository’s Git history before release, then create and re-scan a separate public export.

[Explore the repository](https://github.com/B0yko/go-public)

---

## [The leak may be in the history.](https://boiko.ai/work/go-public/#the-leak-may-be-in-the-history)

Removing a credential from the current files does not remove it from old commits. go-public checks a private repository before it becomes public, looking for secrets, personal data, organization identifiers, local paths, binary metadata, and license history.

It works as a CLI and a Claude Code plugin. The audit runs locally and leaves the source repository unchanged.

## [Inspect what could ship.](https://boiko.ai/work/go-public/#inspect-what-could-ship)

The scanner walks Git refs, commit messages and authors, and unique blobs across history. Its report redacts sensitive findings and points to the objects and locations that need review. It can also inspect unreachable objects when requested.

After a person reviews the findings and fixes the current files, the tool creates a separate export, scans that export again, and produces a verification report. It does not push or publish the repository.

## [What the checks showed.](https://boiko.ai/work/go-public/#what-the-checks-showed)

On five held-out synthetic seeds, the full-history scan found all 595 expected findings with no false positives; a HEAD-only scan found 200. A separate squash-export check confirmed removal of 515 history-only findings across those seeds.

The author also built the detectors and synthetic fixtures, so these results are an upper bound rather than a guarantee for an arbitrary repository. Split or encoded secrets, archives, and text embedded in images remain among the blind spots.

[Synthetic scan results](https://github.com/B0yko/go-public/blob/2ac562ab2162ea16018a61f9f13c9092c44634fa/bench/results/synthetic-small-2-6.md)[Export verification](https://github.com/B0yko/go-public/blob/2ac562ab2162ea16018a61f9f13c9092c44634fa/bench/results/export-verify-small-2-6.md)[Limitations](https://github.com/B0yko/go-public/blob/2ac562ab2162ea16018a61f9f13c9092c44634fa/README.md#limitations)

Source: [https://boiko.ai/work/go-public/](https://boiko.ai/work/go-public/)
