AivexaNewsSearch
AI news for builders and product teamsChecked every hour

Secret protection must scale with software

Collected Oct 7, 2026

GitHub published an essay on secret protection, stating that one in three pull requests on its platform currently involves an AI agent, compared with fewer than one in 10 a year earlier. The company said that if this pace continues, most code pushed to GitHub could be written by an agent within two years, and much of it may never be fully read by a human.

The essay draws on nine complete quarters of data. Between Q2 2024 and Q2 2026, screened pushes grew 2.84 times while pushes carrying credentials grew 2.59 times. Across that period, GitHub found no statistically detectable trend in per-push credential prevalence. Over the same period, the share of push-path blocks overridden by developers fell linearly from 6.63% to 3.93%.

GitHub also introduced a fine-tuned classifier built with Microsoft Applied Sciences to extend push protection to unstructured secrets. The model assesses a whole set of candidate secrets in less than two milliseconds and could more than double the number of secrets GitHub can prevent, according to the company. GitHub also said a new secret appears in publicly visible code about once every two seconds, doubling yearly for the past three years.

The source also lists three other GitHub items: ReviewBench, an open benchmark for AI code review agents built on representative GitHub pull requests with multi-source ground truth and production-aligned metrics; advice for three skills to strengthen as AI changes developer work; and a GitHub Copilot app for beginners explaining how to build custom workflows with canvases by describing an interface in plain English.

Why it matters: Developers and teams relying on GitHub push protection may see broader detection of unstructured secrets. The data suggests faster code creation is not accompanied by more per-push credential leaks or more override willingness, but the volume of pushes carrying credentials is rising.

Read at GitHub Blog · AI & ML

Based on reporting from the original publisher. Visit the source for full context and later updates.

Publisher excerpt

Developers aren’t becoming more careless; they’re being outpaced. The tools that let developers create more software should also take on more of the work of protecting it. The post Secret protection must scale with software appeared first on The GitHub Blog .