News with an accent.

A blue mascot with goggles flies among green cubes, next to a shield with a check mark.
Privacy

GitHub will use AI to block passwords before they reach code

A classifier reads the surrounding code to stop credentials with no fixed format. It is in private preview and meant for paying organizations.

GitHub announced on Oct. 7 that "push protection", the filter that checks every code push so credentials do not slip in, will begin detecting passwords with no fixed format. It will do so with an AI classifier, according to GitHub's blog.

Until now the feature recognized secrets with a known shape, such as the keys of certain services. A database password has no pattern, so the model, a ModernBERT tuned with Microsoft Applied Sciences, reads the surrounding code to decide whether a value looks like one. GitHub says it only evaluates candidates and does not generate code or text.

Who gets it

The blocking feature is in private preview. Later in October it will reach customers with GitHub Secret Protection, on Enterprise Cloud or on the Team plans, and it consumes AI credits; the text does not give a dollar price. Those who already had AI detection move to the new model from Oct. 7. The same model ships in GitHub Enterprise Server 3.23, in public preview, and is added to Copilot's `/security-review` command, which does not require the plan.

The figures are GitHub's

GitHub says the classifier evaluates batches of candidates in under 2 milliseconds and could more than double the secrets that push protection manages to prevent, a projection and not a measured result. According to GitHub, the feature today stops about 30% of newly detected secrets at the door of the history; the remaining 70% is found once already exposed. Revoking one by hand takes about 40 days on average, and one in five takes more than 90.

Volume is also growing: between the second quarter of 2024 and the second quarter of 2026, pushes screened in public code multiplied by 2.84 and those carrying credentials by 2.59. In the second quarter of 2026, 0.47% of pushes carried credentials.

There is no independent evaluation and no published precision or false-positive rates, and Help Net Security draws its data from the same announcement. The exact date of the expansion remains unspecified.

Keep reading

El Mediático counts visits without cookies, with its own measurement and with Google Analytics, which receives basic data about your visit. Only if you accept does Google Analytics also store cookies and, where advertising is active, show personalized ads. You can accept all, reject all, or choose what to allow. The cookie policy is available in Spanish only. More about cookies (Spanish)