01 What happened
GitHub says AI-detected Password alerts have moved to a fine-tuned secret detection model that reads surrounding code to find likely credentials. Customers with those alerts were upgraded automatically. According to GitHub, the model does not generate code or prose.
02 Key details
- The model reads surrounding code to identify likely credentials, including passwords without a recognizable token format. According to GitHub, it does not generate code or prose.
- AI-detected secrets in push protection are in private preview. According to GitHub, AI-based secret scanning with the /security-review command for Copilot CLI and Copilot app will be available soon in private preview. GitHub also plans to bring AI-detected alerts to GHES 3.23 in public preview.
- AI-detected secret alerts will remain included in GHSP and GHAS at no additional charge. The new opt-in push protection and security review checks will consume GitHub AI Credits.
- Push protection is planned for GitHub Enterprise Cloud or GitHub Teams customers with a GHSP or GHAS purchase. An administrator must enable it, subject to organization or enterprise policies. New security review secret checks are off by default, and running /security-review does not enable them.
03 Why it matters
For teams using GitHub secret protection, this could broaden detection of unstructured credentials such as passwords. Before enabling anything, check plan eligibility, admin policies and AI Credit budgets. The source includes no independent accuracy results.
04 Who it matters to
Information security specialists and system administrators.
Original sourceGitHub Copilot