Secret protection must scale with software
GitHub introduces an AI-powered classifier to scale secret protection as AI agents increasingly write code, aiming to prevent leaks before they occur and reduce manual remediation efforts.
GitHub reports that one in three pull requests now involves an AI agent, up from fewer than one in ten a year ago, signaling a rapid shift in code creation practices. The company argues that as agents accelerate software development, protection tools must also evolve to prevent credential leaks before they enter public repositories. A new fine-tuned classifier, developed with Microsoft Applied Sciences, assesses candidate secrets in under two milliseconds, potentially doubling the number of preventable exposures by identifying unstructured secrets earlier in the development process.
Data from nine quarters shows no increase in per-push prevalence of secrets despite a 2.84-fold rise in screened pushes and a 2.59-fold rise in credential-bearing pushes between Q2 2024 and Q2 2026. The share of push-path blocks overridden by developers declined from 6.63% to 3.93%, suggesting developers are not becoming more careless but are instead relying on automated protections. Public scanning now reports an average of 26 credential matches per second, with partners like OpenAI, Google Cloud, and Slack revoking exposed tokens immediately upon notification.
Push protection intervenes before credentials enter repository history, blocking recognizable secrets in real time and giving developers or agents a chance to correct mistakes. In the past month, push protection blocked at least one secret per second, and when including additional secret types, it stops about 30% of newly detected secrets before they are exposed. The remaining 70% are detected only after the credential is already compromised, highlighting the need for earlier intervention to reduce unbounded post-exposure costs.
GitHub’s new ModernBERT classifier, integrated into push protection, evaluates candidate secrets in context without generating code or prose, achieving high precision and low latency. The feature, currently in private preview, will launch later this month for organizations with GitHub Secret Protection across Enterprise Cloud and GitHub Teams, consuming AI credits. The model aims to scale protection alongside AI-driven code creation, reducing the manual effort required to secure credentials as software production accelerates.