AI NewsDev toolsAnnouncement

GitHub ships ModernBERT secret classifier, says it doubles what push protection catches

GitHub says a new ModernBERT classifier assesses candidate secrets in under two milliseconds and will more than double the number of secrets push protection prevents, ships in private preview now, and reaches GitHub Secret Protection customers later this month.

AI News

Editorial3 min read

LinkedInX
GitHub Security Invertocat blocks a Copilot icon

Image: GitHub

Why it mattersA team that was accepting regular leaked tokens because the old pattern-matcher stopped only the clearest cases now has a classifier that reads context, so the question changes from whether to turn push protection on to whether anything should still be allowed through.

A credential that an AI agent generates on a Monday and quietly commits on a Tuesday is still a credential a human has to rotate, and the mean time to do so is still measured in weeks. GitHub is shipping a fine-tuned ModernBERT classifier for push protection. Author Erin Havens writes that the model "assess candidate secrets in context, without generating code or prose", evaluating batches "in under two milliseconds", and will "more than double the number of secrets that we're able to prevent" over pattern-based detectors alone.

Where and when it ships

The classifier is in private preview now. GitHub says that "later this month, the feature will be available to organizations with GitHub Secret Protection across Enterprise Cloud and GitHub Teams", and that it will consume AI credits. For air-gapped setups the model ships with GitHub Enterprise Server 3.23 in public preview.

A smaller addition that touches more users: GitHub is adding the classifier to the /security-review command in the Copilot CLI and Copilot App, so a Copilot user can catch a secret before a push without owning an organisation Secret Protection plan. Over time this is the piece most individual developers will meet first.

The numbers GitHub puts behind the change

Three figures explain why the push for a smarter detector happened now. "One in three pull requests on GitHub involves an AI agent," per the post, up from "fewer than one in 10" a year ago. "A new secret appears in publicly visible code about once every two seconds, doubling yearly for the past three years." And at scale, "2026 Q2, 574M pushes, 0.47% with secrets".

Screening is keeping pace with volume: screened pushes grew 2.84 times while pushes carrying credentials grew 2.59 times. Push-path block overrides, the moments a developer sees a block and tells push protection to let it through anyway, fell from 6.63 percent to 3.93 percent over nine quarters. And "push protection stops about 30% of newly detected secrets before they enter repository history", which the post uses to show how much the classifier can still improve on.

What stays painful if the classifier does nothing new

"The mean time to manually revoke a secret hovers around 40 days; roughly one in five took more than 90 days." That gap is the window during which a committed token is live, and no detector change moves it. The point of the ModernBERT addition is to shrink the share of secrets that reach a repository at all, so the 40-day clock starts less often, and the one in five that live three months becomes rarer because the base of leaks is smaller.

Reading the vendor claim

GitHub is both the owner of the problem and the maker of the fix. Two framings in the post are the vendor's own and read as such: "developers aren't becoming more careless; they're being outpaced" (the opening framing), and the "more than double" line on the classifier's prevention rate (an internal measure, not yet reproduced by anyone else).

The second claim is the one worth watching. If independent audits of GitHub Secret Protection users show the prevention rate roughly doubling over the next two quarters, the ModernBERT addition is the biggest practical change to source-tree security on the platform this year. If the rate moves five or ten points, it is a useful upgrade and well short of a doubling. Either way, the switch from pattern matching to classification that reads surrounding context is the shift, and the next detector change is likely to continue it.

Source

Secret protection must scale with software, Erin Havens, The GitHub Blog.

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX