Skip to content
GitHub Enhances Push Protection with AI to Prevent Credential Leaks

GitHub Enhances Push Protection with AI to Prevent Credential Leaks

First seen 8 Oct 2026, 10:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 11:32 UTC
  • •GitHub's AI detector aims to prevent credential leaks during code pushes.
  • •The new classifier can identify unstructured secrets in under two milliseconds.
  • •Expanded push protection will be available for Enterprise Cloud and Team plans later in October.

GitHub has introduced an AI-based detector, developed with Microsoft Applied Sciences, to prevent developers from inadvertently uploading passwords and other credentials to code repositories. This ModernBERT-based classifier enhances GitHub's existing push protection by identifying unstructured secrets in code, which traditional checks may miss. GitHub reports that a new secret appears in publicly visible code every two seconds, with the number of public code pushes screened increasing by 2.84 times from Q2 2024 to Q2 2026. The new classifier can evaluate potential secrets in under two milliseconds and is expected to more than double the number of secrets prevented from entering repository history. The expanded push protection feature is currently in private preview and will be available later in October 2026 for organizations using GitHub Secret Protection on Enterprise Cloud and GitHub Team plans. GitHub aims to reduce the average manual revocation time of exposed credentials, which currently averages around 40 days.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-08
GitHub announces AI detector for push protection
GitHub revealed a new AI-based classifier to enhance push protection against credential leaks, developed with Microsoft Applied Sciences.
Feeds2.Feedburner
2026-10-08
Expanded push protection in private preview
The new push protection feature will be available later in October for organizations using GitHub Secret Protection.
github.blog

More articles in this cluster (2)

Common questions

How does the AI detector work?
The AI detector uses a ModernBERT-based classifier to identify unstructured secrets in code, analyzing surrounding code for context.
When will the new feature be available?
The expanded push protection feature is expected to be available later in October 2026 for eligible organizations.
What is the average time to revoke exposed credentials?
Currently, the average manual revocation time for exposed credentials is around 40 days.