Skip to content
Sıfırıncı Dakika
Latest

GitHub scales secret protection for the age of AI agents

SecurityNew2 min read
GitHub Blog

In brief

GitHub introduced a fine-tuned classifier built with Microsoft Applied Sciences that extends push protection to unstructured secrets, assessing candidate secrets in under two milliseconds. According to GitHub, this could more than double the number of secrets it can prevent. The company also shared nine quarters of data on secret leaks as code creation accelerates.

  • Fine-tuned classifier built with Microsoft Applied Sciences
  • Push protection extended to unstructured secrets
  • Assesses candidate secrets in under 2 milliseconds
  • Could more than double the number of secrets prevented
  • Secret scanning partnership program with 150+ technical partners
  • Automatic token revocation with partners

Agents are accelerating code creation

According to GitHub, one in three pull requests on the platform now involves an AI agent. A year ago, that number was fewer than one in 10. If that pace holds, most of the code pushed to GitHub could be written by an agent within the next two years, and much of it may never be fully read by a human.

Secret leaks are rising, but developers are not careless

GitHub's nine quarters of data show that a new secret appears in publicly visible code about once every two seconds, doubling yearly for the past three years. But the company pushes back on the claim that developers have become careless: between Q2 2024 and Q2 2026, screened pushes grew 2.84 times while pushes carrying credentials grew 2.59 times. No statistically detectable trend was found in per-push prevalence. Moreover, the share of push-path blocks overridden by developers fell from 6.63% to 3.93%.

Human remediation cannot scale

The mean time to manually revoke a secret hovers around 40 days, and roughly one in five took more than 90 days. As code creation accelerates, exposed credentials can remain usable for weeks or months. According to GitHub, telling developers to be more careful cannot solve that problem on its own.

What the new classifier does

GitHub introduced a fine-tuned classifier built with Microsoft Applied Sciences. The model assesses a whole set of candidate secrets in less than two milliseconds and extends push protection to unstructured secrets. According to GitHub, this could more than double the number of secrets it can prevent.

Partnership program and automatic revocation

GitHub's secret scanning partnership program covers more than 150 technical partners. In Q2 2026, public scanning reported an average of 26 credential matches a second. Once notified, many secrets such as OpenAI API keys, Google Cloud account credentials, Slack webhooks, Hugging Face user tokens and SendGrid keys can be revoked without waiting for a developer to process a GitHub alert.

Why it matters

As AI agents accelerate code creation, secret leaks are rising too; this story explains with data why developers and security teams should rely more on automated protection.

Sources

  1. GitHub BlogFirst reported byPrimary source
    Secret protection must scale with software

Related stories