Skip to content
worth noting New models

GitHub is moving checks for leaked credentials to a new specialized model

clearly official source

Starting on the day of the announcement, GitHub is automatically moving existing AI credential checks to a new model. They remain available to GHSP and GHAS customers at no additional charge. According to the company, the model uses the context of the surrounding code to recognize passwords that lack a typical format.

On the day of the announcement, GitHub is beginning an automatic transition of existing AI checks that detect credentials in code to a new specialized model. These checks remain included in GHSP and GHAS at no additional charge; customers do not need to enable the transition manually.

According to GitHub, the model reads the surrounding code and looks for likely credentials, including passwords without a recognizable format. It does not generate code or text in the process. The company also plans to make alerts based on this model available in GHES 3.23 in public preview, included in the existing GHSP and GHAS license.

What changed

Why it matters

According to the company’s description, the check may also detect passwords that cannot be recognized by a typical format. This is useful when searching for credentials directly in code; however, the source does not provide accuracy measurements or evidence of the scale of the improvement.

Two audiences, two different impacts

What this means

01

For individuals

According to the company, the new model may alert developers working in covered repositories to passwords that lack a typical format. The transition requires no change to their workflow.

More practical updates →
02

For a business

For businesses, the model used in existing security checks is changing without any additional charge for these checks on top of GHSP or GHAS. The change affects credential protection while keeping existing licensing costs unchanged.

Risks and compliance More business impacts →
GHAS GHSP GitHub

Check the original

Event sources

clearly official source · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
GitHub Copilot Changelog primary source · first detected Purpose-built model for leaked secret detection