Live
Kubernetes Operations Under AI Pressure: Aligning Dev and Ops in Hybrid Edge EnvironmentsBeyond Fast Fixes: Building a Closed‑Loop AI SRE Process for Real ReliabilityContext‑aware AI secret detection model rolls out to GitHub push protection and Copilot security reviewClaude Haiku 5.5 on Amazon Bedrock: Faster, cheaper sub‑agent model for production AI workloadsGitHub Copilot adds local sandboxing to CLI, app, and VS Code – implications for engineersReal‑time ACL Enforcement in Amazon Quick and Bedrock Knowledge BasesThree‑Layer AI Vulnerability Pipeline: From Raw Findings to Actionable AlertsEnforcing Evidence‑Based Triage with an AI Vulnerability Steering FileKubernetes Operations Under AI Pressure: Aligning Dev and Ops in Hybrid Edge EnvironmentsBeyond Fast Fixes: Building a Closed‑Loop AI SRE Process for Real ReliabilityContext‑aware AI secret detection model rolls out to GitHub push protection and Copilot security reviewClaude Haiku 5.5 on Amazon Bedrock: Faster, cheaper sub‑agent model for production AI workloadsGitHub Copilot adds local sandboxing to CLI, app, and VS Code – implications for engineersReal‑time ACL Enforcement in Amazon Quick and Bedrock Knowledge BasesThree‑Layer AI Vulnerability Pipeline: From Raw Findings to Actionable AlertsEnforcing Evidence‑Based Triage with an AI Vulnerability Steering File
GitHub

Context‑aware AI secret detection model rolls out to GitHub push protection and Copilot security review

AI SummaryPowered by AI

GitHub’s new purpose‑built AI secret detection model now powers existing password alerts and is being added to push‑time protection and Copilot security‑review checks in private preview. Practitioners must enable the opt‑in features, monitor AI Credit consumption, and adjust policies to incorporate pre‑commit secret scanning.

GitHub has introduced a purpose‑built model for AI secret detection that reads surrounding code to spot credentials, including password strings that lack a recognizable token format. The model is now the default for existing AI‑detected password alerts, and it is being added to push‑time protection and the Copilot /security‑review command in private preview, with billing tied to GitHub AI Credits for the new opt‑in checks.

New model and feature availability

The fine‑tuned secret detection model is automatically applied to all customers who already receive AI‑detected password alerts, at no extra charge. Two additional capabilities are being rolled out in private preview:

  • Push protection: scans unstructured credentials at push time and can block or warn before a secret enters repository history.
  • Copilot security review: the /security‑review command will include secret classifier findings alongside existing LLM‑based checks.

Both features require an explicit opt‑in. The push protection preview is limited to GitHub Enterprise Cloud or Teams customers with a paid GitHub Secret Protection (GHSP) or GitHub Advanced Security (GHAS) license. The Copilot preview does not require GHSP/GHAS, but it does require a Copilot subscription that supports the security‑review command.

AI secret detection in push protection

When enabled, the push protection check runs on every push, reading the diff to locate potential secrets. The check can consume AI Credits even if it does not block the push. Credit consumption is billed to the organization that owns the repository, except for user‑namespace repositories managed by enterprise‑managed users, where the pusher’s allocated credits are used. Usage appears under the “Secret Protection AI Credits” SKU in the AI usage insights.

Credit consumption and billing impact

All existing AI‑detected secret alerts remain included in GHSP and GHAS without additional cost. The new opt‑in checks—push protection and the Copilot security‑review secret classifier—will draw from the organization’s AI Credit pool. Billing starts once the public preview is opted into and the feature is enabled. For Copilot, the AI Credit usage is added to the existing Copilot plan’s consumption and reported under GHSP in the usage insights.

Operational considerations for push protection and Copilot security review

Enabling these checks requires administrative action and must respect any existing organization or enterprise policies. Because the checks are read‑only and do not generate code or prose, they do not alter the existing CI/CD pipeline logic, but they do add a latency component at push time and during the /security‑review invocation. Teams should monitor AI Credit consumption to avoid unexpected spend, especially since credits can be used even when a push is not blocked. The security‑review command remains off by default; teams must explicitly opt in where plan and policy allowances exist.

Related CloudNinjas coverage: AI engineering.

What This Means For Practitioners

Adopt the new model by confirming that your GHSP/GHAS licenses are active and that you have opted into the private preview for push protection if you need pre‑commit secret checks. For Copilot users, enable the secret‑classifier option in the /security‑review command only after reviewing credit impact and policy constraints. Track AI Credit usage in the usage insights dashboard to ensure budgets are respected. Finally, update your incident response playbooks to include the possibility of a secret being flagged at push time rather than after it has been committed.

Originally published atGitHub Changelog