Trusence Every claim has a source
Last updated 7 October 2026 Search Türkçe
← All stories
Security

GitHub adds a faster secret classifier as AI changes code review traffic

GitHub is trying to catch more exposed credentials earlier as AI agents and push volume keep rising.

GitHub says secret protection has to keep pace with AI-driven code creation, and it is backing that up with new data and a new classifier for unstructured secrets. The company says one in three pull requests now involves an AI agent, up from under one in 10 a year earlier, while screened pushes grew 2.84x and pushes carrying credentials grew 2.59x between Q2 2024 and Q2 2026 without a clear rise in per-push prevalence. GitHub also says the share of push-protection blocks overridden by developers fell from 6.63% to 3.93%, and that public scanning in Q2 2026 reported an average of 26 credential matches per second. To catch more secrets before they land in history, GitHub built a fine-tuned classifier with Microsoft Applied Sciences that evaluates candidate secrets in under two milliseconds and could more than double the secrets it can prevent.

Why it matters

That shifts secret protection from a mostly reactive check to one that has to work at much higher speed and volume. For teams using GitHub, the practical change is that more pushes and more AI-involved pull requests are being screened, while a new classifier aims to spot unstructured secrets before they reach history. GitHub says this could prevent more secrets without slowing the process down.

Sources

  • GitHub Blog