GitHub adds AI to catch passwords before a code push
GitHub is adding a ModernBERT classifier to push protection to block unstructured passwords before they enter repositories.
GitHub and Microsoft Applied Sciences built a ModernBERT classifier that expands push protection beyond recognizable credential formats to unstructured secrets such as database passwords. GitHub says the model scores batches in under two milliseconds and could more than double the secrets push protection blocks. From Q2 2024 to Q2 2026, screened public pushes rose 2.84 times and credential-bearing pushes rose 2.59 times, while about 30 percent of newly detected secrets are blocked before they enter history. The capability is in private preview, with a later-October rollout for GitHub Secret Protection on Enterprise Cloud and Team plans, and it will ship in GitHub Enterprise Server 3.23.
- ModernBERT spots unstructured secrets that format-based checks miss.
- Classifier evaluates secret batches in under two milliseconds.
- Push protection blocks about 30 percent of newly detected secrets.
- Private preview now; Enterprise Cloud and Team rollout later in October.
- Screened public pushes grew 2.84 times from Q2 2024 to Q2 2026.
Full article503 words · extracted from helpnetsecurity.com · click to collapse
GitHub has announced an AI detector, developed with Microsoft Applied Sciences, to help prevent developers from uploading passwords and other credentials to code repositories.
The ModernBERT-based classifier will expand GitHub’s push protection, which checks code for secrets and can block a push before a credential enters repository history.
How the detector works
Existing checks recognize many credentials by their formats. The new classifier examines surrounding code to identify unstructured secrets, such as database passwords with no recognizable pattern.
GitHub says the classifier evaluates batches of possible secrets in under two milliseconds and could more than double the number of secrets that push protection can prevent.
“Push protection intervenes earlier. It stops recognizable credentials before they enter repository history, giving the developer or agent a chance to correct the change before there’s an exposure to investigate,” Erin Havens, Product Manager at GitHub, wrote.
False alarms can interrupt developers and undermine trust in future warnings. GitHub must account for accuracy, speed, processing capacity and operating costs when detecting secrets.
More code, more exposed credentials
GitHub says a new secret appears in publicly visible code roughly every two seconds. From the second quarter of 2024 to the second quarter of 2026, the number of public code pushes it screened increased by a factor of 2.84. Pushes containing credentials increased by a factor of 2.59.

Public pushes, Q2 2024–Q2 2026. Push prevalence is the share with a detected secret. Covers supported provider patterns, including GitHub’s own tokens. (Source: GitHub)
Over those nine quarters, the company found no statistically detectable trend in the share of pushes containing secrets.
Across the broader range of secret types GitHub detects, push protection blocks about 30% of newly detected secrets before they enter repository history. The remaining 70% are detected after exposure.
An exposed credential can give someone access to a database, cloud service or other connected system. Developers may then need to disable it, replace it and investigate whether it was misused.
Manual revocation takes around 40 days on average, with roughly one in five exposed secrets taking more than 90 days. Some service providers revoke credentials automatically when GitHub reports an exposure.
Availability and rollout
The expanded push protection is in private preview. GitHub plans to make it available later in October to organizations with GitHub Secret Protection on Enterprise Cloud and GitHub Team plans. The feature will consume AI credits.
The company began automatically updating organizations already using AI secret detection to the new model. Alerts from scans performed after a push remain included in their secret scanning purchase at no additional cost.
The model will ship in public preview with GitHub Enterprise Server 3.23, providing AI-detected alerts to Secret Protection customers, including those running air-gapped environments.
GitHub is adding the classifier to the /security-review command in Copilot CLI and Copilot App. This will let Copilot users check for secrets before pushing code without requiring an organization’s GitHub Secret Protection plan. AI credit usage will be attributed to GitHub Secret Protection in AI usage insights.