GitHub Swaps in a Purpose-Built Secret Detection Model — and New Checks Will Bill AI Credits
On October 7, 2026, GitHub moved secret detection to a purpose-built ModernBERT classifier: AI-detected alerts upgrade automatically at no extra charge, while AI checks in push protection and Copilot's /security-review enter private preview and will bill AI Credits per run. This piece breaks down the three changes, how context-aware detection works, the billing ledger, and what it means for vibe coding developers.

On October 7, 2026, GitHub slipped a quiet but weighty update into its changelog: secret detection is getting a purpose-built small model. Buried in the same announcement is an even more consequential line — two new AI-powered secret checks will start consuming GitHub AI Credits. For the first time, GitHub is putting a security capability on a per-call billing shelf.
Three changes landed in one post: alert scans silently upgraded, AI detection moving into push protection, and a secret classifier joining Copilot's /security-review. On the billing side, one thing stays the same and two things change. The unchanged part: customers already using AI-detected Password alerts get automatically upgraded to the new model — no price hike, still included in GitHub Secret Protection (GHSP) and GitHub Advanced Security (GHAS). The two changes are both opt-in checks: once you turn them on, they bill AI Credits per run.
Three Changes, All at Once
1. Alert scanning: automatic upgrade, no price hike
Organizations already using AI secret detection alerts were switched to the new model starting October 7. Post-push AI-detected secret alert scans remain included in GHSP and GHAS purchases at no additional charge. Think of this one as an "existing-customer benefit": new model, same bill.
GitHub Enterprise Server gets the upgrade too. GHES 3.23 will ship the new model in public preview, bringing AI-detected alerts to Secret Protection customers even in air-gapped environments — also included in their existing GHSP/GHAS purchases, no extra charge.
2. Push protection: AI detection enters private preview, GA later this month, metered billing
This is the check at push time, before a secret ever enters repository history. The new AI detection targets unstructured credentials — bare passwords with no recognizable format — which is exactly the blind spot of classic push protection. Private preview is live now; GitHub says it will reach general availability later in October for Enterprise Cloud and Teams organizations with GHSP. An administrator has to enable it, subject to the organization's or enterprise's policies.
3. /security-review: the secret classifier comes aboard, personal Copilot plans included
Inside a Copilot CLI or Copilot App session, /security-review is a read-only security review command: it scans your active changes, surfaces security vulnerabilities, and returns prioritized findings with remediation suggestions. Coming soon are checks from the secret classifier — and the detail that matters most is that no GHSP or GHAS license is required. Personal Copilot plans (Pro, Pro+, Max, Free, and Student) are all in scope. This is the most "crossover" line in the whole announcement: AI secret detection breaks out of the org-tier security bundle and lands directly with individual developers.
Everything is off by default. GitHub is blunt about it: running /security-review won't switch the new checks on. You have to opt in where your plan and policies allow. If you want in, first confirm you're on the private preview list.
GitHub 密钥检测从正则走向专用小模型
From Pattern-Matching to Reading Context: What the Small Model Actually Does
For the better part of a decade, the workhorse of secret detection has been "recognizing formats": provider templates from more than 150 technical partners (what an AWS key looks like, what a Slack webhook looks like), fixed prefixes, regular expressions, entropy checks. That combination is deadly accurate on issuer-defined tokens — but it has a natural blind spot: things with no fixed format at all. Your database password carries no ID card; to a regex, it's indistinguishable from random noise.
The new model flips the approach: stop recognizing the format, start reading the context. It's a ModernBERT-based classifier, trained jointly by GitHub and Microsoft Applied Sciences. It does exactly one thing — read the code surrounding a candidate string and judge whether it looks like a genuine credential. And note what it pointedly does not do: no code generation, no prose. A pure classifier, not a large language model.
GitHub's technical essay gives an intuitive demo: the same check blocks password-like values in a database URL, a Kubernetes Secret manifest, and a Dockerfile, while letting a changeme placeholder sail through. What separates the two isn't the string itself — it's the context. The variable name, the field name, the semantics of the surrounding configuration. That is precisely what regexes and entropy scores cannot do: they can only inspect what a string looks like, never the kind of code the string lives in.
So why not just throw a big model at the problem? GitHub product manager Erin Havens frames it as the "four-body problem": precision, latency, throughput, and cost are coupled constraints. The push sits on the critical path of development. A check that's too slow makes developers wait; too expensive, and the platform can't afford to run it at scale; too many false positives, and nobody trusts the fourth warning after ignoring the first three. The ModernBERT classifier's answer: a whole batch of candidates evaluated in under two milliseconds — scanning every suspicious string in a push takes less time than pressing Enter. Because it's cheap enough to run on the critical path, GitHub can credibly claim the capability could more than double the number of secrets that push protection prevents.
The essay's thesis is worth pocketing: the tools that let developers create more software should take on more of the work of protecting it. That single sentence is the logic behind the entire update.
And the numbers explain GitHub's urgency. A new secret shows up in publicly visible code roughly every two seconds. Between Q2 2024 and Q2 2026, the public pushes GitHub screened grew 2.84x, while pushes carrying credentials grew 2.59x. Push protection today stops about 30% of newly detected secrets; the other 70% are discovered after exposure — and each exposure takes an average of 40 days to revoke and rotate, with roughly one in five dragging past 90 days. The interception window is those two milliseconds before the push.
The Billing Ledger: Who Pays This Time
The changelog states the bottom line plainly: AI-detected secret alert scans stay included in GHSP and GHAS at no additional charge, while the new opt-in checks for push protection and the security review command will consume GitHub AI Credits. In ledger language:
| Check | Metered? | Billed to |
|---|---|---|
| AI-detected secret alert scans (post-push) | No — included in GHSP/GHAS | Unchanged |
| AI detection in push protection (at push time) | Yes — consumes AI Credits | The organization owning the repository |
New checks in /security-review | Yes — consumes AI Credits | Your Copilot plan's billing account |
A few easy-to-miss details, each worth memorizing:
- Push protection bills the org, never the individual. Usage is attributed to the organization that owns the repository — it won't touch any specific developer's personal credit allocation. There is exactly one exception: user-namespace repositories of enterprise-managed users (EMUs), where usage is attributed to the pusher and comes out of their own allocation.
- You pay per run, blocked or not. A check consumes credits even when it doesn't block the push. The meter runs on "the check ran," not "the check caught something." Repositories with frequent pushes should do this math before opting in.
/security-reviewusage lands on your Copilot bill. In AI usage insights it's reported under GHSP, but the payer is your active Copilot plan's billing account. Personal users: check your plan's credit balance first — the Free tier's allocation is not generous, and one enthusiastic full-repo scan could eat the month.- The SKU is called "Secret Protection AI Credits." For audits, budgets, and billing questions, that's the name to look for.
- Budget alerts don't stop usage by themselves. Admins can set SKU-level budgets under Billing and licensing (product: Advanced Security, SKU: Secret Protection AI Credits), or an all-AI-Credits budget spanning multiple SKUs. But GitHub is explicit: alerts alone don't stop the meter. For a hard cap, you need to enable "Stop usage when budget limit is reached."
- Already in the push protection private preview? Once billing takes effect, continued use consumes credits. If you don't want the charge, disable it beforehand — don't wait for the invoice to find out.
The announcement also carries one line written for the agent era: agents shouldn't enable credit-consuming features or change policies or budgets without explicit authorization. It's the first time a security feature's documentation has included a clause about an agent's spending authority. That sentence deserves its own section — see below.
密钥防护开始按 AI Credits 计费
What It Means for Vibe Coding Developers
For individual developers, the barrier drops and the ledger gets closer. AI secret detection used to be an org-tier exclusive; now personal Copilot plans — even Free and Student — can opt in. But the credits come out of your own Copilot allocation. Check the balance before you flip the switch.
On workflow: pin /security-review ahead of every commit, push, and pull-request review request. It's read-only — it won't touch your code — and once the secret classifier lands, it adds one more net before secrets enter repository history. For vibe coders, that's far more reliable than "I'll remember to check." People are unreliable under deadline pressure; checklists aren't.
The deeper reason hides in a number GitHub cites: one in three pull requests now involves an AI agent. Agents write code fast, but they have no human instinct for "that string looks like a password" — they will cheerfully hardcode credentials into config files, docker-compose files, and seed scripts. Guardrails have to move in front of the push, not mop up after a leak that costs an average of 40 days to revoke, rotate, and investigate. In 2026, with agents pushing more and more of your code, those two milliseconds before the push may be the highest-ROI link in your entire security chain.
For organization admins, the to-do list is concrete: set the SKU-level budget in Billing and licensing first, then consider the preview — or disable the new capabilities by policy if you'd rather sit this one out. GitHub is explicit that opting in won't override admin policy controls. Get the order right: read the bill before opening the gate.
Opinion: Security Is Becoming a Pay-Per-Call API
Zoom out, and the real news isn't "the model changed" — it's "the billing changed." For the first time, GitHub has unbundled a security capability into a separately metered, per-call SKU. Security used to be a bundle: buy GHSP or GHAS, everything included. Now the new push protection and /security-review checks are independently metered API calls. That's not a price hike; it's a change in billing granularity. Security is going from "a feature you buy" to "a service you invoke."
Why is this step inevitable? Two ledgers tell the story. Stopping a secret before the push costs one sub-two-millisecond model inference. Cleaning up after the push costs an engineer 40 days of revocation, rotation, and investigation on average — plus all the uncertainty of the exposure window in between. GitHub's essay nails the asymmetry: before a secret crosses the push boundary, the cost of stopping it is small and the decision is binary, block or allow; once it crosses, the same string can authenticate against a real system and the cost is unbounded. When interception costs approach zero and leak costs stay sky-high, turning interception into "callable by default, billed per use" infrastructure is the rational move for a platform — and the only one that can keep pace with the speed at which code is now produced.
And the small model is the precondition for all of it. If every check required a large-model call, the economics of the push path would collapse — per-call billing would never look affordable. The ModernBERT route, faster and more precise than LLM pipelines at a fraction of the cost, is the textbook infrastructure play of the agent era: offload high-frequency, narrow tasks from big models into small models cheap enough to invoke without thinking. GitHub can charge per security check today only because the check costs two milliseconds.
GitHub publishing the billing model weeks ahead of general availability is itself worth noting. It's a message to every administrator: read the bill, set the budget, then open the gate. And that line about agents not enabling credit-consuming features without authorization is the first time a platform has written an agent's spending authority into a security feature's manual. As agents start spending your money, "who authorized it, who pays" becomes a question every platform will have to answer. GitHub just wrote the first precedent. More will follow.
Three judgments for developers. First: leave a line in your budget for "invisible security calls." Know where the credits go, and look for the Secret Protection AI Credits SKU in your AI usage insights. Second: pin /security-review into your fixed workflow instead of relying on memory. Third: personal Copilot users can start planning now — when private preview slots open, opt in early.
Secret detection went from regular expressions to purpose-built small models in a few short years. In the next few, as agents write most of the code, security checks will increasingly become a default action that deducts a credit on every push. GitHub laying the bill on the table today is the best possible timing — while it's still opt-in, get your budgets, policies, and workflows in order. By the day it becomes the default, you'll already be ready.
Sources: GitHub Changelog (October 7, 2026, "Purpose-built model for leaked secret detection"); Help Net Security (October 8, 2026, "GitHub adds AI to catch passwords before a code push"); GitHub Blog ("Secret protection must scale with software," by Erin Havens).
Sources
Related articles

On October 8, 2026, Harness announced the acquisition of select Augment Code assets, with Cosmos becoming the 'Harness Cosmos Software Factory Agent.' This piece breaks down what was bought, how the software factory works, Harness's agent-to-agent loop, and what it means for vibe coders.

Adversa AI disclosed CCI on October 6: malicious instructions hidden in AES-256 ciphertext trick Copilot CLI in autopilot mode into decrypting them in its own runtime and obeying the output as trusted instructions. In the demo, one encrypted page made the agent read a local .env.prod and silently exfiltrate it in 28 seconds. Microsoft's mai-code-1.1-flash fell for it half the time while GPT-5.6 models refused it outright; GitHub reproduced the chain but declined to call it a vulnerability.

Simon Willison shipped a Newsletters index page for his blog almost entirely by voice — chatting with the Codex tab in the ChatGPT desktop app while cooking dinner in his kitchen, barely touching the keyboard. When a top-tier practitioner starts coding with his mouth, voice + agents stop being a gimmick and become real productivity. A teardown of his playbook, where this workflow breaks, and the minimal setup to copy him.