GitHub AI Scans Code for Hidden Passwords Before Commits
Key Takeaways GitHub has launched a new AI-powered ModernBERT classifier to detect hidden passwords within code before commits. This enhancement expands secret protection beyond traditional pattern...
Key Takeaways
- GitHub has launched a new AI-powered ModernBERT classifier to detect hidden passwords within code before commits.
- This enhancement expands secret protection beyond traditional pattern matching, aiming to significantly reduce the number of exposed credentials.
- The feature is currently in private preview and will be rolled out to GitHub Secret Protection customers on Enterprise Cloud and GitHub Team plans in October, utilizing AI credits.
- It processes potential secrets in under two milliseconds, addressing the increasing volume of code generated by developers and AI agents.
GitHub Leverages AI to Bolster Pre-Commit Secret Detection
GitHub, in collaboration with Microsoft Applied Sciences, has unveiled an advanced AI-driven solution designed to identify and block hidden passwords before code is committed to repositories. This new ModernBERT classifier represents a significant evolution in push protection, moving beyond the limitations of traditional pattern-based secret scanning.
Table Of Content
The company asserts that this AI system can scrutinize batches of potential secrets in less than two milliseconds, with the potential to more than double the number of credentials prevented from entering codebases. This initiative, announced on October 7, directly addresses the growing disparity between rapid software development cycles and the imperative for robust credential security.
Addressing the AI-Driven Code Explosion
Microsoft data indicates that approximately one-third of all GitHub pull requests now involve an AI agent. As both human developers and AI tools accelerate code generation, the demand for security checks that are both fast and accurate, without impeding development workflows or necessitating extensive manual reviews, has become critical.
Traditional secret scanning methods typically rely on identifying predefined patterns, such as specific token prefixes or fixed string structures. While effective for many API keys, these methods often fail to detect internal database passwords or other credentials that resemble ordinary strings. The new ModernBERT classifier overcomes this limitation by analyzing the contextual code surrounding a value, enabling it to determine whether a string is likely a credential rather than merely evaluating its format.
GitHub has provided examples demonstrating the model’s capability to pinpoint password-like values embedded in database URLs, Kubernetes Secret manifests, and Dockerfiles, while accurately disregarding placeholder strings like “changeme.”
Speed, Accuracy, and Impact on Development
Unlike generative AI models, this classifier’s function is purely evaluative, classifying candidate secrets rather than creating code. This specialized role makes it exceptionally well-suited for the rapid, on-the-fly checks required during a push attempt. It is important to note that the reported processing speed applies to batches of candidates, not an entire repository scan.
Accuracy is paramount in such systems, as false positives can disrupt development and erode trust in security warnings. GitHub states that its new classifier offers greater precision than its existing large language model pipelines, all while maintaining the speed and cost-efficiency necessary for integration into push protection. However, specific numerical false-positive rates were not disclosed in the announcement.
A review of nine quarters, from Q2 2024 to Q2 2026, revealed a 2.84-fold increase in screened public pushes, alongside a 2.59-fold increase in pushes containing supported credentials. Despite this surge in activity, GitHub found no statistically significant trend in the proportion of pushes containing secrets. Encouragingly, developer overrides of push-protection blocks decreased from 6.63% to 3.93%. These findings suggest that the increased workload stems from heightened development activity rather than a decline in developer vigilance.
Across the broader spectrum of secret types GitHub detects, push protection currently prevents approximately 30% of secrets from entering repository history. The remaining 70% are typically discovered post-commit.
Manual revocation of exposed secrets is a time-consuming process, averaging around 40 days, with about one in five secrets taking over 90 days to address. This highlights that detection alone does not resolve access issues, underscoring the critical need for proactive prevention.
The AI-based push protection is currently in private preview. GitHub plans a broader rollout later in October for GitHub Secret Protection customers on Enterprise Cloud and GitHub Team plans, where it will consume AI credits. Organizations already utilizing AI secret detection will be automatically upgraded, and post-push alerts will continue to be provided without additional cost.
Future plans include public preview alerts in Enterprise Server 3.23, extending to air-gapped environments, and integration with Copilot CLI and the Copilot App’s /security-review command.
It is crucial to remember that prevention of new leaks does not mitigate the risks from past exposures. GitHub’s secret scanning partner program facilitates the reporting and revocation of credentials by providers. For security teams, blocking new vulnerabilities and revoking access to previously exposed secrets remain distinct but equally essential tasks.
What You Should Do
- If you are a GitHub Secret Protection customer on Enterprise Cloud or GitHub Team plans, prepare for the automatic upgrade to AI-based push protection and budget for AI credits.
- Ensure your development teams are aware of the enhanced pre-commit secret detection capabilities and encourage their use to prevent credential leakage.
- Even with enhanced prevention, regularly audit your repositories for historically exposed secrets and work with your providers to revoke compromised credentials promptly.
- Integrate secret scanning and push protection into your CI/CD pipelines as early as possible to minimize exposure windows.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.