GitHub rolls out AI classifier to block secrets before they reach repositories

GitHub has introduced a ModernBERT-based detector, built with Microsoft Applied Sciences, to expand its push protection for credentials. The classifier examines surrounding code to catch unstructured secrets that format-based checks miss, processing candidate secrets in under two milliseconds. GitHub says the tool could more than double the number of secrets blocked before entering repository history.
GitHub's new detector, created with Microsoft Applied Sciences, uses ModernBERT to broaden push protection beyond pattern matching. It inspects nearby code to flag credentials lacking a standard format, for instance passwords for databases, and can assess batches of candidates in less than two milliseconds. GitHub estimates this may more than double the secrets blocked before they become part of a repository's recorded history.
The feature is in private preview and is slated for October availability to Enterprise Cloud and Team organizations with GitHub Secret Protection. It will use AI credits. A public preview is planned with GitHub Enterprise Server 3.23, including air-gapped setups. The classifier is also being added to Copilot CLI and Copilot App's /security-review command.
Developers, organizations, and open-source users could benefit if AI-assisted push protection blocks more credentials before exposure, potentially reducing account takeovers and downstream data breaches. Smaller teams may face new AI-credit costs or limited access, while false positives could interrupt workflows and weaken trust in warnings. Because exposed