GitHub rolled out a new AI classifier built on ModernBERT that detects unstructured secrets, like hardcoded database passwords, that don't follow a fixed pattern, according to a GitHub Blog post published Oct. 7. The model evaluates a candidate secret in under 2 milliseconds, the company said.
The classifier more than doubles the number of secrets caught before they enter a repository's history, compared with GitHub's prior detection methods, GitHub said. It is in private preview now and will roll out later in October to organizations with GitHub Secret Protection, covering Enterprise Cloud and GitHub Team plans, according to the post.
Organizations already using GitHub's AI secret detection get the updated model automatically starting Oct. 7, and GitHub Enterprise Server 3.23 will offer a public preview for air-gapped environments, GitHub said. The detection was also added to the /security-review command in Copilot CLI and the Copilot App, though running it consumes AI credits, according to the company.
"The tools that let developers create more software should also take on more of the work of protecting it," GitHub said in the post.
Unstructured secrets, the ones that don't match a known API key format, are the harder half of the leak-detection problem. GitHub pricing the fix in AI credits rather than giving it away free signals how it expects to charge for AI-era security tooling going forward.