Skip to content

GitHub's new secret-detection model reads code context, and the deeper checks will bill AI credits

· by Pondero Newsdesk

The short version

GitHub swapped its AI-detected secret alerts to a context-reading model at no extra cost on October 7, while confirming that new push-protection and Copilot security-review checks on the same model will consume AI Credits once they leave preview.

GitHub's new secret-detection model reads code context, and the deeper checks will bill AI credits

GitHub switched the model behind its AI-detected secret alerts on October 7 to one that reads the code surrounding a credential instead of matching it against a known token pattern, catching passwords that have no recognizable format at all, at no added cost. GitHub used the same changelog entry to confirm that two new checks riding on that model, AI secret detection in push protection and a secret classifier added to Copilot's /security-review command, will consume GitHub AI Credits once they move out of preview, per GitHub's changelog.

What happened

GitHub's fine-tuned secret-detection model reads the surrounding code to identify likely credentials, including passwords without a recognizable token format, and does this without generating any code or prose of its own, per GitHub's changelog. Three changes landed or were previewed in the same post. First, every customer with existing AI-detected Password alerts was automatically moved onto the new model starting October 7, at no additional charge, and those scans stay included in GitHub Secret Protection (GHSP) and GitHub Advanced Security (GHAS). Second, AI-detected secret alerts are coming to GitHub Enterprise Server 3.23 in public preview, also included with an enterprise's existing GHSP or GHAS purchase. Third, two credit-billed checks moved into preview on the same model: AI secret detection in push protection, which scans for unstructured credentials at push time before they enter repository history, is now in private preview; and a secret classifier inside Copilot's /security-review command, for the Copilot CLI and Copilot App, is described as coming soon in private preview. GitHub said it published the billing details for both ahead of their broader rollout specifically so admins can review access and spending before turning them on.

The push-protection bill lands on the repo's owner, not the pusher

For the new push-protection checks, GitHub Credit usage is attributed to the organization that owns the repository rather than to whichever developer triggered the push, with one exception: enterprise-managed users on user-namespace repositories have usage attributed to the pusher against that person's own allocated credits, per GitHub's changelog. A check can consume credits even when it does not end up blocking the push, so a noisy repository can rack up usage without a single alert to show for it. Billing only starts once an organization opts into the public preview and turns the feature on, and an administrator has to enable it in the first place, subject to whatever policy the org or enterprise has set.

The Copilot-side check works differently. No GHSP or GHAS license is required to use it, since it runs inside the existing /security-review command available to Copilot subscribers. Usage is billed to whichever account holds the active Copilot plan and shows up under GHSP in that account's AI usage insights. Both checks are off by default, so simply running /security-review will not turn on the new classifier, and GitHub's own guidance for coding agents is explicit that they should not enable credit-consuming features or change budgets without a human's authorization. Org and enterprise admins can disable either capability by policy and set a dedicated spending budget, and GitHub says opting in will not override those controls. The practical move for a team evaluating either preview is to set that budget or policy first, since usage can accrue the moment the feature is live, not only when it fires a visible alert.

Context

The model change sits inside GitHub's broader secret-scanning product, which has relied on regex-style pattern matching for structured secrets like API keys and tokens for years; this release targets the harder case of unstructured credentials, plain-text passwords with no fixed shape, that pattern matching alone tends to miss. GitHub frames the push and said the detection needs to "keep pace with the way you build software, whether you write code yourself or work with an AI agent," tying the release to the same AI-assisted coding wave that is driving more code, and more accidental secrets, into repositories faster than manual review can catch them.

Eligibility for the two new checks runs wider than a typical GHAS feature. Push protection still requires a paid GHSP or GHAS license on GitHub Enterprise Cloud or GitHub Team, per GitHub's changelog, but the Copilot security-review classifier does not: it reaches individual Pro, Pro+, Max, Free, and Student plans, plus Copilot Business and Copilot Enterprise, with no separate security license attached. GitHub Enterprise Server customers get only the free side of the release for now, since AI push protection and the Copilot security-review command are both absent from the GHES 3.23 scope; the server platform's upgrade is limited to the automatic AI-detected-alert swap.

What to watch next

GitHub said AI Credit usage for the push-protection checks will be introduced "in the coming weeks," so the actual price per check has not been set yet. The security-review classifier has no stated preview date beyond "coming soon." Both are worth tracking once GitHub publishes the credit rate: that number determines whether scanning every push for unstructured secrets is a rounding error or a real new line item for teams that enable it broadly.

Sources