An overlooked password in source code can put company systems at risk without triggering a security warning.
GitHub announced Oct. 7 that it has upgraded existing AI-detected password alerts with a new model designed to identify credentials that pattern-based scanners may miss. AI push protection is in private preview, with additional Copilot checks coming soon in private preview.
For security teams, catching a credential before it is pushed can prevent an exposure. Finding it afterward may require revoking the credential, updating affected applications, and investigating possible misuse.
Surrounding code offers clues about hidden credentials
Conventional scanners recognize many API keys and access tokens through identifiable patterns. Internal passwords may lack those markers, making them difficult to distinguish from ordinary text in application files.
GitHub developed a new classifier with Microsoft Applied Sciences using ModernBERT, a model that examines surrounding code to determine whether a string is likely to contain a credential. Examples include passwords in database URLs, Kubernetes Secret files, and Dockerfiles. It can also distinguish likely credentials from placeholders such as changeme.
Unlike generative AI tools that produce code or text, the classifier evaluates whether candidate strings are likely to be secrets. GitHub says the classifier evaluates batches of candidate secrets in under two milliseconds. That figure describes the model’s processing time, rather than the duration of a complete security check. False positives and missed credentials remain possible.
GitHub tests earlier checks for password leaks
Existing push protection stops about 30% of newly detected secrets before they enter repository history when additional secret types are included, according to GitHub's analysis. Around 70% are discovered after being committed. Previous investigations into exposed Git repositories have also found active cloud and payment credentials stored in accessible repository data.
GitHub outlines three ways the classifier will be used:
- Secret scanning alerts. Existing customers with AI-detected password alerts have automatically received the upgraded model to identify potential credentials in repositories covered by the feature.
- Push protection. Available in private preview, AI checks can identify unstructured credentials when developers push code and potentially block them before they enter repository history.
- Copilot security reviews. An upcoming private preview will add the classifier to the /security-review command in Copilot CLI and the Copilot app, allowing developers and AI coding agents to check changes for exposed secrets before committing or pushing code.
Existing AI-detected alerts remain included with GitHub Secret Protection and GitHub Advanced Security at no additional charge. GitHub plans to introduce AI Credit billing for the new opt-in push protection and Copilot checks in the coming weeks. Existing private-preview users will also consume credits if they continue using AI push protection after the billing change takes effect. Push checks can consume credits even when no push is blocked.
AI push protection is intended for eligible GitHub Team and Enterprise Cloud customers with paid security coverage and administrator approval. Copilot's upcoming classifier checks will not require those security licenses, although eligible Copilot access is necessary. GitHub Enterprise Server 3.23 is also expected to receive AI-detected alerts in public preview, without the new push protection or Copilot checks.
Security teams still need a plan for exposed credentials
If your organization develops software using GitHub, a leaked password could provide access to connected services, depending on its permissions. A public GitHub repository linked to a CISA contractor reportedly contained government cloud credentials and internal deployment information.
Application security teams and repository administrators should take the following steps:
- Check which repositories are protected. Confirm that secret scanning and push protection are enabled where appropriate. Include contractor-managed repositories, personal projects containing company code, and automated development workflows. Identify who can override warnings and how those exceptions are recorded.
- Revoke exposed credentials and investigate possible misuse. Removing a password from the latest code does not necessarily eliminate it from earlier commits. Teams should revoke the exposed credential, issue a replacement, and examine relevant account or service logs for unauthorized activity. Confirm which applications use the credential before closing the incident.
- Extend credential protection across development. Researchers previously found more than 10,000 Docker Hub images exposing sensitive secrets, demonstrating how credentials can escape through other development artifacts. Store active credentials in dedicated secret-management services, limit their permissions, and apply security checks to both human-written and AI-generated code.
Security teams should prioritize alerts according to the access an exposed credential could grant. An inactive test value and a working production password do not pose the same threat, and the response should account for that difference.
More cybersecurity news: A new authentication report finds password use remains widespread even among professionals responsible for defending accounts and systems.





