GitHub previews AI checks to block passwords before code reaches repository history
The ModernBERT classifier targets credentials that lack recognizable patterns. Push-time checks will consume AI credits; broader access is planned for later in October.
GitHub’s ModernBERT classifier judges possible credentials using surrounding code, aiming to catch passwords that pattern-based checks miss while avoiding false alarms on placeholders. Built with Microsoft Applied Sciences, it evaluates candidate batches in under two milliseconds; GitHub says it could more than double the secrets blocked by push protection. The integration remains in private preview, with a planned late-October 2026 rollout for eligible Secret Protection customers; checks will use AI credits, so accuracy, trust and usage cost remain practical constraints.
01
GitHub reports that current push protection stops about 30% of newly detected secrets, while manual revocation takes an average of about 40 days.
02
From Q2 2024 to Q2 2026, screened uploads grew 2.84 times and credential-bearing uploads grew 2.59 times; GitHub found no detectable rise in the share containing secrets.
03
The classifier is also being added to post-upload scanning and Copilot’s /security-review command; Enterprise Server 3.23 will include it in public preview.
Passwords that lack recognizable patterns could soon be blocked before they enter GitHub repository history, rather than discovered afterward. On October 7, GitHub introduced a ModernBERT-based classifier built with Microsoft Applied Sciences. Its push-protection integration is in private preview, and GitHub says it could more than double the number of secrets the platform prevents.
Reading the code around a password
Push protection stops recognizable credentials when developers or agents upload code, before those credentials enter repository history. But an internal database password may have no identifying pattern. GitHub’s new classifier examines candidate secrets alongside surrounding code, making a contextual judgment without generating code or prose.
GitHub’s demonstration shows the model blocking password-like values in a database URL, a Kubernetes Secret configuration file and a Dockerfile, while allowing the placeholder changeme. The distinction is between a value that appears to be a credential and one used as sample text—not simply whether a string resembles a password.
The company says the classifier evaluates candidate batches in under two milliseconds and is more precise than its existing large-language-model detection pipelines. Speed is only one constraint. A false alarm interrupts a developer and can weaken trust in the next warning; GitHub also has to balance accuracy, processing volume and cost.
Prevention versus cleanup
About 30%Secrets stopped before repository history
GitHub says existing push protection stops about 30% of newly detected secrets when additional secret types are included.
About 40 daysMean time to manually revoke a secret
GitHub reports that manual revocation averages about 40 days; roughly one in five secrets took more than 90 days.
More uploads, not a clear rise in carelessness
GitHub’s case for earlier detection rests on growing activity, not evidence that each upload has become riskier. Between Q2 2024 and Q2 2026, screened uploads grew 2.84 times, while uploads carrying credentials grew 2.59 times. Across nine quarters, the company found no statistically detectable trend in the share containing secrets.
Developers also became less likely to override a block: that share fell from 6.63% to 3.93% over the same period. GitHub argues these findings challenge the idea that agents are making developers more careless. Its proposed response is to prevent more exposures automatically as the amount of code grows.
One classifier, different access and billing
GitHub plans to make the push-protection feature available later in October 2026 to organizations with GitHub Secret Protection on Enterprise Cloud and GitHub Teams. These checks will consume AI credits, with usage attributed to Secret Protection in AI usage insights. Other deployments have different terms:
Post-upload scanning: Starting October 7, organizations with AI secret detection receive the model automatically. Alerts remain included with secret scanning at no additional cost.
Enterprise Server: Version 3.23 will include the model in public preview, supporting AI-detected alerts for Secret Protection customers in environments isolated from external networks.
Copilot: GitHub is adding the classifier to the /security-review command in Copilot CLI and Copilot App, without requiring an organization’s Secret Protection plan.
Sources
github.blogSecret protection must scale with software
Reader comments
Newest comments first. Replies stay oldest first.