What happened
On Oct 7, GitHub (with Microsoft Applied Sciences) announced an AI classifier that extends push protection to unstructured secrets: a ModernBERT-based model evaluates surrounding code to flag password-like values in database URLs, Kubernetes Secret manifests and Dockerfiles, evaluating candidate batches in under 2ms and positioned to more than double secrets prevented. It is in private preview (Enterprise Cloud/Team Secret Protection customers later in October), and ships in public preview in GitHub Enterprise Server 3.23, including air-gapped environments, plus the Copilot CLI /security-review command.
Why it matters
With one in three GitHub PRs now involving an AI agent, credential leaks scale with AI code output; pattern-only scanning misses internal database passwords. This pushes detection earlier (block-before-history) where the cost is a binary decision rather than an unbounded multi-week manual revocation, and it extends to Copilot CLI for agent-authored pushes.
Applicability
AppSec and platform teams on GitHub Enterprise should opt into AI-based push protection at October general preview, budget AI-credit consumption, and test precision against their own codebase before enforcing hard blocks; air-gapped Enterprise Server 3.23 customers get it in public preview.