Developer, Coding & Automation · GitHub · October 7
GitHub brings context-aware secret detection closer to the commit
A specialized classifier expands credential detection, with separate rollout and billing rules for new checks.
Tools: GitHub Copilot · GitHub Secret Protection
What happened
GitHub announced a purpose-built model that reads code context to identify likely secrets, including credentials without familiar token patterns. Existing AI-detected alerts move to the model under current Secret Protection coverage. AI push protection is in private preview, and added secret checks for Copilot security review were announced as coming soon in private preview. New opt-in checks are planned to consume AI Credits; included alert scans remain separate.
Roseram analysis
Finding a password before it enters history can reduce exposure, but a classifier cannot establish that every credential is absent. Builders should retain conventional scanners and rotate any exposed secret. Availability and cost also need separate checks: an existing security license does not automatically enable every new agent feature, and budget alerts are not necessarily spending caps.