GitHub Secret Scanning Got a New AI Model. Its Documented Blind Spots Predate It.
On 7 October 2026 GitHub put a fine-tuned secret detection model behind GitHub secret scanning. Per the changelog, it reads the code around a candidate string to judge whether it is a credential, including passwords that follow no recognizable token format, and it generates no code or prose. Customers who already had AI-detected password alerts were moved onto it automatically, at no extra charge under GitHub Secret Protection or GitHub Advanced Security.
Nobody had to opt in, so the question for a security lead is not whether to adopt it. It is what the detector you are now running skips. The changelog does not say. The docs page that does was last edited on 24 September, thirteen days before the swap, and its list of exclusions is a shortened copy of an older one.
What shipped in GitHub secret scanning on October 7
Three surfaces, with different availability and different bills:
- AI-detected alerts. Switched to the new model on GitHub.com that day, still included in GHSP and GHAS. GitHub Enterprise Server 3.23 gets the model in public preview, also included.
- AI push protection. Private preview, for GitHub Team and Enterprise Cloud with paid GHSP or GHAS. An administrator has to turn it on. It consumes AI Credits billed to the organization that owns the repository, and the changelog states that a check can consume credits even when it does not block the push. Pushes to user-namespace repositories of managed users are charged to the pusher instead. It is not part of the GHES 3.23 release.
- Secret checks in Copilot's /security-review. Coming in private preview for Copilot CLI and the Copilot app. They are off by default, running /security-review does not switch them on, they need no GHSP or GHAS license, and their credits land on the Copilot plan's billing account.
The budget note is the line worth acting on today. A SKU-level budget for Secret Protection AI Credits sends alerts, but alerts alone do not stop usage; you have to set the option that stops usage at the limit. Teams already in the push protection preview will start consuming credits when billing begins unless they disable it first.
What the detector skips, according to the artifact
The changelog links to no limitations. The place GitHub documents them is the application card for its security and quality AI features. Under AI secret detection it lists two limits: the model may miss credentials, and it may not detect secrets in test code. It then says detections are skipped when certain conditions are met, such as a file path containing test, mock or spec, and a file extension from a list of eleven: .cs, .go, .java, .js, .kt, .php, .py, .rb, .scala, .swift and .ts.
Read literally, that list says the detector skips every Python and TypeScript file. The docs repository shows that is not what the rule meant. In December 2024 a commit titled as a clarification rewrote the rule to say detections are skipped only when both conditions are met, joining the two bullets with an explicit AND. The rule is a source file in a test-looking path, not either one.
The last version of the standalone page, before a June 2026 commit migrated it into the application-card template, carried more than that rule. It also said the detector:
- stops raising new alerts for a file once five or more of its detections are closed as false positives
- skips generated and vendored files
- skips encrypted files
- skips SVG, PNG, JPEG, CSV, TXT, SQL and ITEM files
None of those four survived the migration, and neither did the word both. The card's history shows edits on 19 August and 24 September, the latter opening the card to GHES 3.23, and nothing since the October 7 model swap.
So the honest status of each old exclusion is unknown in both directions. The new model may have dropped the SQL and TXT skips, or it may still apply all of them and the docs simply lost the sentences. GitHub has not published which.
Why the blind spots are where credentials live
How much sits in those zones is checkable. GitHub's own code search counts 70,528 indexed conftest.py files on public default branches that contain the word password. That file name meets both halves of the test rule, since conftest contains test and the extension is .py. The count does not say how many are live secrets. That is the problem: a fixture password and a production password pasted into a fixture look the same to a path filter.
This is the evaluation line item from the PoC-to-production gap: silent degradation is the default failure mode, and the only defense is a repeatable test you own. GitHub replaced the model under existing customers without publishing an evaluation of it, and the application card describes its quality process in terms of resolution rate and latency on coding tasks, not recall on credentials. Your coverage may have improved. You cannot tell from anything GitHub has printed.
The verdict: keep it, measure it, cap it
The central claim here is that, as of 10 October, nothing GitHub has published states what the model now running skips: the only coverage rules on record were written before 7 October, and the current page carries one of five of them. A GitHub page dated on or after 7 October that lists the new model's exclusions would show this wrong.
Leave the alerts on; they cost nothing extra. Before enabling AI push protection, do three things.
Count the files the documented rule would skip, from the root of a repository:
git ls-files | grep -iE '(test|mock|spec)' | grep -iE '\.(cs|go|java|js|kt|php|py|rb|scala|swift|ts)$' | wc -l
git ls-files | grep -iE '\.(svg|png|jpe?g|csv|txt|sql|item)$' | wc -l
The docs do not say whether the path match is case-sensitive, so the -i flag errs toward counting more. If either number is large, cover those paths with a custom pattern or a second scanner rather than assuming the model reads them.
Plant a fake, never-valid password in a scratch private repository, once in tests/conftest.py and once in config/settings.py, and see which raises an alert. That is your own boundary test, and it costs nothing under the included alerts.
Set the Secret Protection AI Credits budget with stop-at-limit enabled before anyone opts into push protection, because a check that blocks nothing still bills.
Sources
- Purpose-built model for leaked secret detection - GitHub Changelog
- Application card: GitHub security and quality AI features - GitHub Docs (the artifact)
- Commit history of the application card source - github/docs
- Clarifying secret scanning conditions, December 2024 - github/docs commit
- Responsible AI page for generic secret detection, last version before the June 2026 migration - github/docs
- Enabling generic secret detection for AI-detected secrets - GitHub Docs
- Push protection - GitHub Docs
- GitHub code search: password in conftest.py files (third-party public repositories)
Related reading
- Dev Tools
Your GitHub Copilot Settings Change Meaning on October 22. Unconfigured Will Mean On.
By Petru Popa · Read - Dev Tools
Node 20 EOL Reached GitHub Actions on September 23. Your node20 Actions Kept Passing.
By Petru Popa · Read - Dev Tools
Copilot Custom Agents Pinned to Retiring Models: Aim at the LTS, Not the Suggested Alternative
By Petru Popa · Read
Turn this into a plan for your team.
One week, fixed fee: a working session with your team, a prioritized use-case backlog, and an ROI model for the opportunities worth chasing.