AI Briefing
KOSign in

GitHub introduces ModernBERT classifier to potentially double secret prevention at push

·2026.10.08 02:45

Key point

The new model assesses candidate secrets in under two milliseconds and is available in private preview for Enterprise Cloud and Teams.

1 / 2

Details

As one in three pull requests on GitHub now involves an AI agent, the platform is scaling its security measures to match the accelerated rate of code creation. GitHub has introduced a new ModernBERT classifier developed with Microsoft Applied Sciences to extend push protection to unstructured secrets, potentially more than doubling the number of prevented exposures.

The Scaling Challenge

Data from the past nine quarters shows that while screened pushes grew 2.84 times between Q2 2024 and Q2 2026, the prevalence of secrets per push remained statistically stable. This indicates developers are not becoming more careless but are being outpaced by the volume of code. Currently, push protection stops about 30% of newly detected secrets, leaving 70% to be found after they enter repository history, where remediation requires significant human effort.

Technical Implementation

The new classifier addresses the "four-body problem" of secret protection: precision, latency, throughput, and cost. Unlike previous LLM-based pipelines, the ModernBERT model assesses candidate secrets in context without generating code or prose. Key performance metrics include:

  • Latency: Evaluates candidate batches in under 2 milliseconds.
  • Precision: More precise than existing pipelines, reducing false positives that interrupt developer workflows.
  • Cost Efficiency: Designed to run at scale in the critical path of push operations.

Availability and Integration

The feature is currently in private preview and will be available later this month to organizations with GitHub Secret Protection across Enterprise Cloud and GitHub Teams, consuming AI credits. Additionally:

  • Organizations with AI secret detection are automatically updated to the new model for post-push scans at no additional cost.
  • The model will ship with GitHub Enterprise Server 3.23 in public preview, supporting air-gapped environments.
  • It is being added to the /security-review command for Copilot CLI and Copilot App, allowing users to address secrets before a push.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.