Agents are accelerating code creation
According to GitHub, one in three pull requests on the platform now involves an AI agent. A year ago, that number was fewer than one in 10. If that pace holds, most of the code pushed to GitHub could be written by an agent within the next two years, and much of it may never be fully read by a human.
Secret leaks are rising, but developers are not careless
GitHub's nine quarters of data show that a new secret appears in publicly visible code about once every two seconds, doubling yearly for the past three years. But the company pushes back on the claim that developers have become careless: between Q2 2024 and Q2 2026, screened pushes grew 2.84 times while pushes carrying credentials grew 2.59 times. No statistically detectable trend was found in per-push prevalence. Moreover, the share of push-path blocks overridden by developers fell from 6.63% to 3.93%.
Human remediation cannot scale
The mean time to manually revoke a secret hovers around 40 days, and roughly one in five took more than 90 days. As code creation accelerates, exposed credentials can remain usable for weeks or months. According to GitHub, telling developers to be more careful cannot solve that problem on its own.



