GitHub updates secret detection model and previews push protection checks
Reviews

GitHub updates secret detection model and previews push protection checks

TechNews Editorial
TechNews EditorialOct 8, 2026 · 1 min read
Share

Why it matters

GitHub says the private-preview push check can flag unstructured credentials before they enter repository history.

The facts

  • GitHub says its new model uses surrounding code to identify likely credentials, including passwords without a recognizable token format.
  • Existing AI-detected Password alert customers have been upgraded; alert scans remain included with Secret Protection and Advanced Security.
  • AI push protection is in private preview, and GitHub plans AI Credit usage for opt-in checks in the coming weeks.

GitHub has upgraded existing AI-detected Password alerts to a new model that reads surrounding code to identify likely credentials. The company says it can find passwords even when they lack a recognizable token format. AI secret checks using the model are also available in private preview for push protection.

Existing customers with AI-detected Password alerts were upgraded automatically. GitHub says these alert scans remain included with GitHub Secret Protection and GitHub Advanced Security at no additional charge. The model identifies likely secrets without generating code or prose.

Push checks examine code before it enters a repository

The new push protection check looks for unstructured credentials when code is pushed, giving developers a chance to remove a secret before it enters repository history. It is available in private preview to GitHub Enterprise Cloud and GitHub Team customers with paid Secret Protection or Advanced Security coverage. An administrator must enable it, subject to organization or enterprise policies.

GitHub plans to introduce AI Credit usage for the opt-in push checks in the coming weeks. A check can consume credits even if it does not block a push. Customers already using the private preview will consume AI Credits if they continue using it after the billing change takes effect, according to GitHub.

A push check finishes without blocking the code submission, while the available AI credit balance decreases.
Illustration: AI & Tech News

Copilot security reviews will gain secret checks

GitHub also plans to add checks from the model to the Copilot security-review command in supported Copilot CLI and Copilot App sessions. The command reviews active changes for security vulnerabilities and suggests fixes. The added secret checks will be off by default and will consume AI Credits on top of the review’s existing usage. They will not require a Secret Protection or Advanced Security license.

Organization and enterprise administrators will be able to disable the new capabilities by policy and set AI Credit budgets. GitHub also plans to bring AI-detected alerts to GitHub Enterprise Server 3.23 in public preview, included with an enterprise’s existing Secret Protection or Advanced Security purchase.

Source: GitHub

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading