GitHub Copilot: New AI Model for Secret Detection
GitHub released a purpose-built, fine-tuned model for leaked secret detection that reads surrounding code to identify likely credentials, including passwords with no recognizable token format. Customers with AI-detected Password alerts were upgraded automatically, AI push protection is in private preview, and AI secret checks in the Copilot /security-review command are coming soon. The new opt-in checks consume GitHub AI Credits, while AI-detected alerts stay included with Secret Protection and Advanced Security.
Key Takeaways
- GitHub shipped a fine-tuned model built only for secret detection, not a general-purpose LLM.
- It catches passwords and unstructured credentials by reading the surrounding code.
- Existing AI-detected Password alert customers were upgraded automatically.
- AI push protection is in private preview and stops secrets before they enter repository history.
- Copilot's /security-review command will gain secret checks that need no Secret Protection license.
- New opt-in checks consume GitHub AI Credits, while AI-detected alerts remain free with Secret Protection or Advanced Security.
A Model Built for Finding Secrets
GitHub released a fine-tuned model designed specifically for secret detection. It reads the code around a potential secret to decide whether something is a likely credential, including passwords that have no recognizable token format. The model does not generate code or prose. The goal is context-aware detection across more developer workflows.
Availability
Customers who already had AI-detected Password alerts were upgraded to the new model automatically. AI-detected secrets in push protection are in private preview. AI-based scanning through the Copilot /security-review command, for Copilot CLI and the GitHub Copilot app, is coming soon in private preview. AI-detected alerts are also coming to GitHub Enterprise Server 3.23 in public preview, included with existing Secret Protection or Advanced Security purchases.
AI Secret Detection in Push Protection
Push protection with AI checks for unstructured credentials at push time, so secrets can be removed before they enter repository history. It is available to GitHub Enterprise Cloud or GitHub Team customers with GitHub Secret Protection or Advanced Security, and an administrator must enable it.
AI Secret Checks in /security-review
The Copilot /security-review command runs before committing, pushing or requesting a pull request review. It performs a read-only review of active changes and returns prioritized findings with remediation suggestions, and developers or coding agents can fix confirmed findings and rerun it. Secret classifier checks are coming soon as an addition to the existing LLM-based review. They do not require a Secret Protection or Advanced Security license, consume AI Credits, and are billed to the active Copilot plan's billing account. These checks are off by default.
Billing and Controls
AI-detected secret alerts remain included with Secret Protection and Advanced Security at no extra charge. The new opt-in checks for push protection and security review consume GitHub AI Credits, with usage starting in the coming weeks. Credits show up under the "Secret Protection AI Credits" SKU. Administrators can disable the capabilities by policy and set budgets under Billing and licensing, then Budgets and alerts; enabling "Stop usage when budget limit is reached" creates a hard cap. Users already in the push protection private preview will consume credits after the change unless they disable the feature first.