GitHub AI-Powered Password Detection Prevents Leaks During Code Commits
GitHub has deployed a machine learning-based system to identify sensitive data before it is integrated into repositories, enhancing its push protection mechanism.
AI-Driven Secret Detection
GitHub has deployed a machine learning-based system, developed in collaboration with Microsoft Applied Sciences, to identify sensitive data before it is integrated into repositories. This enhancement expands the platform’s existing push protection mechanism, which scans code for confidential information and can halt commits before credentials are stored in version history.
ModernBERT-Based Classifier
The new system employs a ModernBERT-based classifier to analyze code context and detect unstructured secrets such as database passwords that lack standardized formats. Traditional methods rely on pattern recognition, but this classifier evaluates potential secrets in under two milliseconds, significantly increasing the volume of detected credentials.
Push Protection Enhancements
Push protection now intervenes earlier in the development workflow, preventing recognizable credentials from entering repository history and allowing developers to correct errors before exposure occurs. Erin Havens, a GitHub product manager, emphasized that early intervention reduces the risk of security incidents by addressing issues prior to code integration.
Accuracy, Speed, and Resource Efficiency
The system balances accuracy, speed, and resource efficiency to minimize false positives that could disrupt workflows. GitHub reports that a new exposed secret appears in public code approximately every two seconds.
Statistics on Credential Exposure
Between the second quarter of 2024 and the second quarter of 2026, the volume of public code pushes analyzed by the platform grew by 2.84 times, while commits containing credentials increased by 2.59 times. Despite this growth, no significant trend in the proportion of pushes with secrets was observed over nine quarters.
Push Protection Effectiveness
Push protection blocks roughly 30% of newly identified secrets before they are stored in repositories, leaving 70% to be detected post-exposure. Exposed credentials can grant unauthorized access to databases, cloud services, or connected systems, requiring developers to revoke, replace, and investigate compromised tokens.
Rollout and Availability
Manual revocation processes take an average of 40 days, with 20% of cases exceeding 90 days. Some service providers automatically invalidate credentials when GitHub reports exposures. The updated push protection is currently in private preview and will roll out to organizations using GitHub Secret Protection on Enterprise Cloud and GitHub Team plans later in October.
AI Credits and Integration
The feature will utilize AI credits, with existing AI secret detection users automatically upgraded to the new model. Post-push scan alerts remain included in secret scanning subscriptions without additional costs. The classifier will also be available in the public preview of GitHub Enterprise Server 3.23, offering AI-generated alerts to Secret Protection customers, including those in isolated environments.
Conclusion
Integration with the /security-review command in Copilot CLI and Copilot App enables developers to check for secrets before commits without requiring a GitHub Secret Protection plan. AI credit usage will be tracked through GitHub Secret Protection’s AI usage insights. The initiative reflects broader efforts to address credential exposure in software development workflows, aligning with trends in DevSecOps and AI-enhanced security practices.
“Early intervention reduces the risk of security incidents by addressing issues prior to code integration.” – Erin Havens, GitHub product manager
