Solutions  ·  2026-10-09

GitHub adds AI-powered secret detection to push protection — ModernBERT classifier catches unstructured passwords pre-push

SolutionsMedium impactGlobal
On Oct 7, GitHub (with Microsoft Applied Sciences) announced an AI classifier that extends push protection to unstructured secrets: a ModernBERT-based model evaluates surrounding code to flag password-like values in database URLs, Kubernetes Secret manifests and Dockerfiles, evaluating candidate batches in under 2ms and positioned to more than double secrets prevented. It is in private preview (Enterprise Cloud/Team Secret Protection customers later in October), and ships in public preview in GitHub Enterprise Server 3.23, including air-gapped environments, plus the Copilot CLI /security-review command.
With one in three GitHub PRs now involving an AI agent, credential leaks scale with AI code output; pattern-only scanning misses internal database passwords. This pushes detection earlier (block-before-history) where the cost is a binary decision rather than an unbounded multi-week manual revocation, and it extends to Copilot CLI for agent-authored pushes.
AppSec and platform teams on GitHub Enterprise should opt into AI-based push protection at October general preview, budget AI-credit consumption, and test precision against their own codebase before enforcing hard blocks; air-gapped Enterprise Server 3.23 customers get it in public preview.
GitHub Blog — Secret protection must scale with softwareHelp Net Security — GitHub adds AI to catch passwords before a code push
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →