GitHub adds AI to catch passwords before a code push

GitHub has announced an AI detector, developed with Microsoft Applied Sciences, to help prevent developers from uploading passwords and other credentials to code repositories.

The ModernBERT-based classifier will expand GitHub’s push protection, which checks code for secrets and can block a push before a credential enters repository history.

How the detector works

Existing checks recognize many credentials by their formats. The new classifier examines surrounding code to identify unstructured secrets, such as database passwords with no recognizable pattern.

GitHub says the classifier evaluates batches of possible secrets in under two milliseconds and could more than double the number of secrets that push protection can prevent.

“Push protection intervenes earlier. It stops recognizable credentials before they enter repository history, giving the developer or agent a chance to correct the change before there’s an exposure to investigate,” Erin Havens, Product Manager at GitHub, wrote.

False alarms can interrupt developers and undermine trust in future warnings. GitHub must account for accuracy, speed, processing capacity and operating costs when detecting secrets.

More code, more exposed credentials

GitHub says a new secret appears in publicly visible code roughly every two seconds. From the second quarter of 2024 to the second quarter of 2026, the number of public code pushes it screened increased by a factor of 2.84. Pushes containing credentials increased by a factor of 2.59.

GitHub push protection

Public pushes, Q2 2024–Q2 2026. Push prevalence is the share with a detected secret. Covers supported provider patterns, including GitHub’s own tokens. (Source: GitHub)

Over those nine quarters, the company found no statistically detectable trend in the share of pushes containing secrets.

Across the broader range of secret types GitHub detects, push protection blocks about 30% of newly detected secrets before they enter repository history. The remaining 70% are detected after exposure.

An exposed credential can give someone access to a database, cloud service or other connected system. Developers may then need to disable it, replace it and investigate whether it was misused.

Manual revocation takes around 40 days on average, with roughly one in five exposed secrets taking more than 90 days. Some service providers revoke credentials automatically when GitHub reports an exposure.

Availability and rollout

The expanded push protection is in private preview. GitHub plans to make it available later in October to organizations with GitHub Secret Protection on Enterprise Cloud and GitHub Team plans. The feature will consume AI credits.

The company began automatically updating organizations already using AI secret detection to the new model. Alerts from scans performed after a push remain included in their secret scanning purchase at no additional cost.

The model will ship in public preview with GitHub Enterprise Server 3.23, providing AI-detected alerts to Secret Protection customers, including those running air-gapped environments.

GitHub is adding the classifier to the /security-review command in Copilot CLI and Copilot App. This will let Copilot users check for secrets before pushing code without requiring an organization’s GitHub Secret Protection plan. AI credit usage will be attributed to GitHub Secret Protection in AI usage insights.

Don't miss