From the source
GitHub announced a new purpose-built model for detecting leaked secrets, which reads surrounding code to identify likely credentials including passwords without a recognizable token format.
The model is being integrated into secret scanning alerts, push protection, and GitHub Copilot security reviews.
AI-detected secret alerts remain included in GHSP and GHAS at no additional charge, while opt-in checks for push protection and the security review command will consume GitHub AI Credits.



