Safety·EASYHUB JOURNAL
GitHub rolls out a purpose-built leaked-secret model that reads code context and expands toward push protection and Copilot security review

What changed
GitHub released a purpose-built, fine-tuned model for secret detection on October 7. It reads surrounding code to identify likely credentials such as passwords that lack recognizable token formats, without generating code or prose. Existing AI-detected Password alerts have automatically moved to the new model; AI secret checks in push protection are in private preview, and the Copilot CLI/App `/security-review` flow is planned to gain the classifier in private preview. Existing AI-detected alerts remain included with GHSP/GHAS, while the new opt-in push-protection and Copilot checks are planned to consume AI Credits. GitHub also plans AI-detected alerts for GHES 3.23 in public preview.
- Original title
- Purpose-built model for leaked secret detection
- Source
- GitHub · github.blog
- Topic
- Safety
- Source month
- 2026-10
This is a concise EasyHub summary of the linked source, not the full report or original reporting. Availability and preview conditions are described in the summary and original.
Summary page published · Editorial information