GitHub has announced an AI-powered detector, built with Microsoft Applied Sciences, to help prevent developers from pushing passwords and other credentials into code repositories. The classifier, based on ModernBERT, is designed to catch unstructured secrets such as database passwords that do not follow recognizable patterns. It expands GitHub’s existing push protection, which blocks known credential formats before they enter repository history.
According to GitHub, a new secret appears in publicly visible code roughly every two seconds. From the second quarter of 2024 to the second quarter of 2026, the number of public pushes screened increased by a factor of 2.84, while pushes containing credentials rose by a factor of 2.59. Despite that growth, GitHub found no statistically detectable trend in the share of pushes containing secrets. Across all detected secret types, push protection blocks about 30% of newly detected secrets before exposure; the remaining 70% are found only after they have already been exposed.
The company acknowledges that false alarms can interrupt developers and undermine trust in warnings, so accuracy, speed, processing capacity, and operating costs all factor into the design. Manual revocation of exposed credentials takes about 40 days on average, with roughly one in five exposed secrets taking more than 90 days. The expanded push protection is in private preview and will become available later in October to organizations using GitHub Secret Protection on Enterprise Cloud and Team plans, consuming AI credits. The model is also planned for public preview with GitHub Enterprise Server 3.23, including air-gapped environments, and will be added to the /security-review command in Copilot CLI and Copilot App.