Level 3 — Git for platforms · wrap-up
Cheat sheet & self-check
Every command from this section on one page.
Hooks and scanning
pip install pre-commit && pre-commit install | Enable the hooks in .pre-commit-config.yaml for this clone |
pre-commit run --all-files | Run every hook on the whole repository |
gitleaks detect --source . --verbose | Scan the repository history for secrets |
gitleaks protect --staged | Scan only what you're about to commit |
Signing
git config --global gpg.format ssh | Sign commits with an SSH key |
git config --global user.signingkey ~/.ssh/id_ed25519.pub | Which key signs |
git config --global commit.gpgsign true | Sign every commit |
git log --show-signature -1 | Check the signature on the last commit |
History clean-up
git filter-repo --path secrets.env --invert-paths | Remove a file from all history (after rotating the secret) |
Faster clones
git clone --depth 1 <url> | Only the latest commit (CI builds) |
git clone --filter=blob:none <url> | Partial clone: file contents fetched on demand |
git sparse-checkout set apps/payments charts/ | Only these folders in the working tree |
git lfs track "*.iso" | Store large binaries outside normal Git objects |
git count-objects -vH | How big the repository really is |
Fix common errors
git pull --rebase && git push | Push rejected (non-fast-forward): integrate first |
git switch -c rescue | In detached HEAD with new commits: keep them on a branch |
ssh -vT git@github.com | Debug SSH authentication step by step |
git config --global core.autocrlf input | Normalise line endings on commit (Linux/macOS) |
git submodule update --init --recursive | Fetch submodules after cloning |