# Git main branch contains accidental commits

**URL:** <https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100>\
**Category:** Developing Nodes\
**Tags:** git\
**Created:** [22 December 2024 09:51 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100 "2024-12-22T09:51:10Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [22 December 2024 09:51 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/1 "2024-12-22T09:51:10Z")

</div>

Hi folks,

I have been doing quite a lot of work in the last week for the dashboard repo, but it seems I have (by accident) pushed some stuff to my main branch. Now the main branch is two commits ahead of the dashboard project:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/9/b/9b2facd587736ef551caf8d3a43d702d9039c35d.png)

Does anybody know how I can fix this? Because when I create now a new branch, the pull request also shows extra changed files ☹

First I was 3 commits ahead, but I managed to get rid of that by a `git reset --hard 01e71c66cd33675f93d654853b87aa3016718a17` command.

But that fails for my other two commits:

```auto
xxx@yyy:~/node-red-dashboard/nodes/config $ git revert 01e71c66cd33675f93d654853b87aa3016718a17
error: commit 01e71c66cd33675f93d654853b87aa3016718a17 is a merge but no -m option was given.
fatal: revert failed

```

Not sure which parent commit I need to supply at the `-m` option. I found some answers on the web about cherry picking commits, but I am afraid that I might perhaps break my pull requests or so... Would be very nice if somebody could get me back on track, so I can create a new pull request!

Thanks!  
Bart

---

<div class="post-metadata">

**Author:** ![GogoVega](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gogovega/32/71313_2.png) [@GogoVega](https://discourse.nodered.org/u/GogoVega)\
**Post date:** [22 December 2024 09:54 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/2 "2024-12-22T09:54:42Z")

</div>

Hi Bart, use

```bash
git reset --soft d27fd37b46a1678fc51a60078adaf96499c29e1b
git push -f

```

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [22 December 2024 09:55 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/3 "2024-12-22T09:55:59Z")

</div>

Within 10 seconds after typing my question, I saw this:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/0/60ca837c4f6cd256b40d377d838ab26157b5285d.png)

What a service 🤩  
Did we have recently a (very high quality!!!) AI bot installed on Discourse 😂

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [22 December 2024 10:11 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/4 "2024-12-22T10:11:01Z")

</div>

@GogoVega,  
Thanks for the fast answer!!  
Mindblowing response time and (as always) a very correct answer.  
Really appreciated!!

That solved it.  
My brain trusts a soft reset more than a hard reset, so I am going to remember that command 😋

For anybody else having the same issue in the future:

1. Just click on the copy button next to the last "good" commit, i.e. to the point where you want to return:

2. Make sure you are on the correct branch locally, in my case `git checkout main`

3. Reset to that commit using `git reset --soft d27fd37b46a1678fc51a60078adaf96499c29e1b`

4. Push your changes to the remote (main) branch on Github `git push -f`

5. Now you can see that the faulty commits are gone:

6. So finally my (main) branch was back in sync with the dashboard main branch (from which my branch was forked):

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [22 December 2024 11:29 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/5 "2024-12-22T11:29:03Z")

</div>

Main branch should always have protections turned on to prevent accidental updates. 😉

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [22 December 2024 11:42 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/6 "2024-12-22T11:42:05Z")

</div>

@TotallyInformation,  
you triggered my attention...  
Do you have any more details about that?

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [22 December 2024 11:49 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/7 "2024-12-22T11:49:34Z")

</div>

The source repository does have this enabled. It would make sense if a fork inherited this setting.

@BartButenaers : [Managing a branch protection rule - GitHub Docs](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/managing-a-branch-protection-rule)

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [22 December 2024 11:56 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/8 "2024-12-22T11:56:49Z")

</div>

The one I tend to use @BartButenaers is **Require a pull request before merging** (as well as others for contributor restrictions)

This forces me to review a PR, before merging into main (even my own commits) - but as the owner, you can bypass - but its asking you to bypass

 ![Screenshot 2024-12-22 at 11.54.54](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/8/4/84ec36b84b57e8c3fa4f196cbbc4fb24d7ef08a2.png)

 ![Screenshot 2024-12-22 at 11.55.32](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/8/7/87ff9761b6ee6ed30e58ae34136ce9380f65f0db.png)

I have some other repos, that has status checks (like code/security scanning) - before it can be approved

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [22 December 2024 12:02 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/9 "2024-12-22T12:02:08Z")

</div>

Yes, that's what I had in mind. As for security checks, I ALWAYS now implement those on any new repo, supply-chain attacks are too common now to ignore this.

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [22 December 2024 12:03 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/10 "2024-12-22T12:03:58Z")

</div>

I have 2 status checks on some other repos of mine.

- CodeQL - We all know that one 😃
- Deep Scan ([https://deepscan.io](https://deepscan.io))

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [22 December 2024 12:14 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/11 "2024-12-22T12:14:01Z")

</div>

Not forgetting Dependabot to check your dependency chain.

I also have "Socket Security" integrated. This is a GitHub connected cloud service so you go to their web site and connect to your GitHub. It is widely used in security circles.

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/7/3/739105e6ea39dfcd6c97d9e57d38ab453ddcd1b5.png)

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [22 December 2024 12:21 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/12 "2024-12-22T12:21:40Z")

</div>

Yup - Dependabot (but gets annoying sometimes) - when the upstream project doesn't stop!  
Still - vital!

Check out Deep Scan - its incredibly fast, and has actually highlighted vulnerabilities deep inside the stack, that I hadn't seen my self.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [22 December 2024 12:23 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/13 "2024-12-22T12:23:34Z")

</div>

> [@marcus-j-davies](#):
>
> Dependabot (but gets annoying sometimes) - when the upstream project doesn't stop!

Agreed. Though you can control it quite well with its comment reply system. I also restricted it a bit more on uibuilder due to the number of dev dependencies.

> [@marcus-j-davies](#):
>
> Deep Scan

Yes, use that too. Of course, you can't always do anything realistic about deep dependencies.

One thing it has made me do though is to work harder to reduce live dependencies. I will generally not use a dependency any more if I can help it. For example, I used to use dependencies for all sorts of utility processing but I don't do that any more. Copilot really helps there as well since it will generally give me just the utility code I need.

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [22 December 2024 12:32 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/14 "2024-12-22T12:32:41Z")

</div>

I tried Deepscan once, and it highlighted the potential for Javascript Injection, where the user supplied value, was later read out of the database and used Server Side.

The value was berried deep, later in my logic.

Since then started using it, and thought it was awesome!

I won't get to off-topic from here - but then, I'm speaking to a Mod 😉

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [22 December 2024 13:56 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/15 "2024-12-22T13:56:21Z")

</div>

> [@Steve-Mcl](#):
>
> The source repository does have this enabled. It would make sense if a fork inherited this setting

That indeed looks better. Thanks!

 ![Screenshot_20241222-145436_Chrome](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/0/5/0575a8d2ea1eb340a568adcc09d17ea965b7a65a.jpeg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [20 February 2025 13:57 UTC](https://discourse.nodered.org/t/git-main-branch-contains-accidental-commits/94100/16 "2025-02-20T13:57:20Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
