GitHub is launching a powerful AI-based tool designed to catch passwords buried in code *before* developers push it to repositories. Built with Microsoft Applied Sciences, the system uses a ModernBERT classifier to identify credentials that traditional pattern detection might miss. The rollout kicks off later in October for teams on GitHub Secret Protection, Enterprise Cloud, and GitHub Team plans.
Why Traditional Secret Scanning Falls Short
Standard secret scanning tools typically hunt by format—recognizing API keys, token prefixes, or fixed character sequences. But many credentials, like database passwords, may look like innocent strings to those systems. The new approach analyzes code context—such as lines around a candidate secret—to determine if it’s likely a real password or just placeholder text.
Early test cases show the model detecting sensitive data in database URLs, Kubernetes Secret manifests, and Dockerfiles—all while ignoring benign placeholders like “changeme.” The system operates quickly, classifying small batches of potential credentials in under two milliseconds. That speed makes it practical to integrate into developer workflows without significant slowdowns.
Trials, Metrics & Availability
Reviewing data from public code pushes between Q2 2024 and Q2 2026, GitHub found that push volume increased nearly threefold, and pushes containing credentials rose about 2.6×. Despite this, the proportion of pushes with secrets stayed relatively stable—suggesting more activity overall, not sloppier behavior. At the same time, override rates for push-protection warnings dropped from 6.63% to 3.93% during that period.
GitHub reports that around 30% of credential leaks are stopped by push protection before entering code history; the remaining 70% are still found afterward. Once a secret enters history, removal is slow: on average it takes about 40 days to revoke exposure, and one in five exposed credentials linger beyond 90 days.
Currently, the new AI-powered push protection is in private preview. It will become available later this month to customers of GitHub Secret Protection on Enterprise Cloud and for GitHub Team plans—using AI credits. Those already using GitHub’s secret detection features will see upgrades automatically. The tool will also reach air-gapped environments and Enterprise Server 3.23 with public-preview alerts, alongside integrations via Copilot CLI and the Copilot App’s security review command.
Importantly, this system is preventive—not corrective. It can block new leaks, but cannot remove secrets already exposed in past commits. Organizations are encouraged to combine push protection with credential revocation programs and secret scanning partner networks to cover both prevention and remediation.
Why it matters: As organizations increasingly leverage AI agents during development, automated credential leaks become a larger threat. This classifier bridges a critical gap: catching secrets that lack known patterns while being fast enough to work in real time. With override rates falling, there’s early evidence developers trust it. If this technology delivers at scale, it could sharply cut the exposure window for credential leaks. But preventing leaks is only half the battle—teams must also improve their post-commit response and revocation practices to fully secure their codebases.