Back to Now
GitHub AI secret detection for push protection launch Verified

GitHub previews AI classifier to block unstructured secrets before code is pushed

A ModernBERT-based detector is in private preview for push protection; GitHub's own measurements suggest exposure volume follows rising code activity.

Why now GitHub disclosed the new classifier and nine quarters of internal secret-scanning data on October 7 at 17:45 UTC.

Detecting credentials before a push

GitHub said on October 7 that it has built a ModernBERT-based classifier with Microsoft Applied Sciences to identify unstructured secrets, such as passwords without a recognizable token prefix, using surrounding code. GitHub says the model evaluates candidate batches in under two milliseconds. The new push-protection use is currently in private preview, with a wider release planned later in October for eligible GitHub Secret Protection customers. Separately, organizations already using post-push AI secret detection are being moved to the new model. GitHub says the classifier could more than double the number of secrets it prevents, but that is a projection rather than a measured outcome of the forthcoming rollout.

More code, more exposure work

GitHub also published nine quarters of its own scanning data. It reports that screened public pushes rose 2.84 times from the second quarter of 2024 to the second quarter of 2026, while pushes carrying detected credentials rose 2.59 times. GitHub says it found no statistically detectable upward trend in the per-push prevalence of credentials, challenging the idea that AI agents have made individual developers more careless. The analysis is GitHub’s, and its detection coverage defines what it can observe. The practical concern is that even a stable exposure rate yields more leaked credentials when code activity rises. How accurately the new classifier handles real repositories and false positives will need assessment after broader access begins.