Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Recover deleted commits from GitHub using REST API, web interface, and git fetch. Use when you have commit SHAs and need to retrieve actual commit content, diffs, or patches. Includes techniques for accessing "deleted" commits that remain on GitHub servers.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 125% | 0% |
| case-18 | ✗→✓ | ▲ Improved | 92% | 0% |
| case-03 | ✓→✓ | = Same ✓ | 65% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 303% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 300% | 0% |
Purpose: Access commit content, diffs, and metadata directly from GitHub when you have commit SHAs. Includes methods for retrieving "deleted" commits that remain accessible on GitHub servers.
SHA Sources: GitHub Archive, git reflog, CI/CD logs, PR comments, issue references, external archives, security reports.
Deleted Commits Are Never Really Deleted:
Rate Limits Matter:
Access a "deleted" commit via web browser:
https://github.com/org/repo/commit/FULL_COMMIT_SHAGet commit as patch file:
bashcurl -L https://github.com/org/repo/commit/FULL_COMMIT_SHA.patch
Query via REST API:
bashcurl -H "Authorization: Bearer $GITHUB_TOKEN" \ https://api.github.com/repos/org/repo/commits/FULL_COMMIT_SHA
GitHub serves "deleted" commits at predictable URLs. These commits show a warning banner but content remains fully accessible.
Commit View:
https://github.com/<ORG>/<REPO>/commit/<SHA>Patch Format (raw diff with headers):
https://github.com/<ORG>/<REPO>/commit/<SHA>.patchDiff Format (unified diff only):
https://github.com/<ORG>/<REPO>/commit/<SHA>.diffExample:
bash# View commit that was force-pushed over curl -L https://github.com/grapefruit623/gcloud-python/commit/e9c3d31212847723aec86ef96aba0a77f9387493 # Download as patch curl -L -o leaked_commit.patch \ https://github.com/grapefruit623/gcloud-python/commit/e9c3d31212847723aec86ef96aba0a77f9387493.patch
Short SHA Access: GitHub allows accessing commits with just 4+ hex characters (if unique):
https://github.com/org/repo/commit/e9c3The GitHub REST API provides structured commit data including file changes, author info, and commit message.
Endpoint:
GET https://api.github.com/repos/{owner}/{repo}/commits/{ref}Example Request:
bashcurl -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer $GITHUB_TOKEN" \ https://api.github.com/repos/org/repo/commits/abc123def456
Response Structure:
json{ "sha": "abc123def456...", "commit": { "author": { "name": "Developer Name", "email": "dev@example.com", "date": "2025-06-15T14:23:11Z" }, "message": "Commit message here" }, "files": [ { "filename": "src/config.js", "status": "added", "patch": "@@ -0,0 +1,3 @@\n+// config" } ] }
Rate Limit Headers:
x-ratelimit-limit: 5000
x-ratelimit-remaining: 4999
x-ratelimit-reset: 1623456789For bulk analysis or when you need full repository context, fetch specific commits via Git.
Minimal Clone + Fetch Specific Commit:
bash# Clone without file contents (just history/trees/commits) git clone --filter=blob:none --no-checkout https://github.com/org/repo.git cd repo # Fetch the specific "deleted" commit git fetch origin <COMMIT_SHA> # View the commit git show FETCH_HEAD # View specific file from that commit git show FETCH_HEAD:path/to/file.txt
Why This Works:
--filter=blob:none: Omits file contents initially (fast clone)--no-checkout: Doesn't populate working directorygit fetch origin <SHA>: Retrieves specific commit even if "deleted"Scenario: You have a list of commit SHAs to investigate and need their content.
pythonimport requests import time def download_commit_patch(repo, sha, token=None): url = f"https://github.com/{repo}/commit/{sha}.patch" headers = {"Authorization": f"Bearer {token}"} if token else {} response = requests.get(url, headers=headers, allow_redirects=True) if response.status_code == 200: return response.text return None # Download patches for a list of commits commits = [ {"repo": "org/repo1", "sha": "abc123..."}, {"repo": "org/repo2", "sha": "def456..."}, ] for commit in commits: patch = download_commit_patch(commit["repo"], commit["sha"]) if patch: with open(f"{commit['sha'][:8]}.patch", "w") as f: f.write(patch) time.sleep(0.5) # Rate limit courtesy
Scenario: Need to verify who actually authored a suspicious commit (committer vs author can differ).
API Query:
bashcurl -s -H "Authorization: Bearer $GITHUB_TOKEN" \ "https://api.github.com/repos/org/repo/commits/SHA" | \ jq '{ author: .commit.author, committer: .commit.committer, verified: .commit.verification.verified }'
Response Analysis:
json{ "author": { "name": "Real Developer", "email": "dev@company.com", "date": "2025-06-15T10:00:00Z" }, "committer": { "name": "CI Bot", "email": "bot@company.com", "date": "2025-06-15T10:05:00Z" }, "verified": false }
Forensic Notes:
git commit --author)Discovery: Security researcher Sharon Brizinov used GitHub Archive to find zero-commit PushEvents, recovering commit SHAs of "deleted" commits. Using GitHub API to fetch commit content, discovered a leaked GitHub PAT token.
Impact: The token had admin access to ALL Istio repositories (36k stars, used by Google, IBM, Red Hat). Could have enabled:
Resolution: Reported via Istio's security disclosure process; token was immediately revoked.
Technique Chain:
before SHAGET /repos/istio/istio/commits/{SHA}.patch/user endpointFrom scanning recovered force-pushed commits, the most impactful secrets found in order:
Files Most Likely to Contain Secrets:
.env, .env.local, .env.productionconfig.js, config.py, config.jsondocker-compose.yml, docker-compose.yamlapplication.properties, application.ymlhardhat.config.js (crypto/web3 projects)403 Forbidden on API requests:
repo for private repos)x-ratelimit-remaining header404 Not Found for commit:
Rate limit exceeded:
x-ratelimit-reset header for Unix timestamp)Web access blocked by WAF:
Git fetch fails for commit:
Other measured skills in the registry, with their headline benchmark lift.