GitHub adds AI secret detection to push protection, blocking leaks in under 2ms
GitHub says one in three pull requests now involves an AI agent, up from fewer than one in ten a year ago, and that between Q2 2024 and Q2 2026 screened pushes grew 2.84x while pushes carrying credentials grew 2.59x — with no statistically detectable trend in per-push prevalence, and the share of push blocks overridden by developers falling from 6.63% to 3.93%. Working with Microsoft Applied Sciences, GitHub built a fine-tuned ModernBERT classifier that judges candidate secrets from surrounding code context in under two milliseconds, which it says could more than double the number of secrets it prevents. The feature is in private preview and arrives later this month for organizations with GitHub Secret Protection on Enterprise Cloud and GitHub Teams, consuming AI credits; it is also coming to GitHub Enterprise Server 3.23 in public preview and to the /security-review command in Copilot CLI and Copilot App.