GitHub push protection adds AI to catch hidden secrets
GitHub is adding an AI classifier to code pushes to stop developers from committing passwords and other credentials to repositories. The detector was built with Microsoft Applied Sciences and is based on ModernBERT.
The model extends push protection, the GitHub feature that scans code for secrets and can block a push before a credential lands in repository history.
Context instead of patterns
Push protection already catches many credentials because they follow known formats. Plenty of secrets do not. A database password, for example, can look like any other string.
The new classifier looks at the code around a candidate string to decide whether it is a secret. GitHub says it processes batches of possible secrets in less than two milliseconds. The company also says it could more than double the number of secrets push protection is able to stop.
"Push protection intervenes earlier. It stops recognizable credentials before they enter repository history, giving the developer or agent a chance to correct the change before there's an exposure to investigate," wrote Erin Havens, Product Manager at GitHub.
Speed is only one constraint. False alarms interrupt developers and make them less likely to trust the next warning. GitHub says it has to weigh accuracy, speed, processing capacity and operating costs when it hunts for secrets.
Leaks grow with code volume
According to GitHub, a new secret appears in publicly visible code about every two seconds. Between Q2 2024 and Q2 2026, the number of public pushes it screened grew 2.84 times. Over the same period, pushes containing credentials grew 2.59 times.
Across those nine quarters, the company found no statistically detectable trend in the share of pushes with secrets. Leaks are rising roughly in line with the volume of code.
Across all secret types GitHub detects, push protection blocks about 30% of newly detected secrets before they reach repository history. The other 70% are only caught after exposure.
A leaked credential can give someone access to a database, a cloud service or another connected system. Developers then have to disable it, replace it and check whether it was abused. Manual revocation takes about 40 days on average, and roughly one in five exposed secrets takes more than 90 days. Some service providers revoke credentials automatically once GitHub reports an exposure.
Rollout and pricing
The expanded push protection is in private preview. Later in October, GitHub plans to open it to organizations with GitHub Secret Protection on Enterprise Cloud and GitHub Team plans. The feature will consume AI credits.
Organizations already using AI secret detection are being moved to the new model automatically. Alerts from scans run after a push stay covered by their existing secret scanning purchase at no extra cost.
The model will also ship in public preview with GitHub Enterprise Server 3.23, the self-hosted edition of GitHub. It will provide AI-detected alerts to Secret Protection customers, including those running air-gapped environments.
GitHub is also adding the classifier to the /security-review command in Copilot CLI and Copilot App. Copilot users can then check for secrets before pushing, even if their organization has no Secret Protection plan. The AI credits used will be attributed to GitHub Secret Protection in AI usage insights.
Our Take
GitHub's own figures suggest the real problem is timing. If 70% of detected secrets are found only after exposure and revocation drags on for weeks, moving detection to the moment before a push could shrink the window attackers have. Havens' mention of "the developer or agent" is telling. As AI tools write and push more code, checks need to work at the speed of those agents, and vendors are building similar guardrails for AI coding agents. Classifiers are not a substitute for keeping credentials out of code, for example with a dedicated secrets manager. It is worth watching how the false-positive rate holds up in practice and whether AI credit costs slow adoption.
