# GitHub — Purpose-built model for leaked secret detection

- Company: GitHub (github.com)
- Announced: 2026-10-07T16:13:56+00:00
- Category: capability-change
- Coverage: not counted
- Announcement: yes
- Group: announcements
- Source: https://github.blog/changelog/2026-10-07-purpose-built-model-for-leaked-secret-detection
- Record: https://forck.live/items/16440-purpose-built-model-for-leaked-secret-detection
- Subject: Copilot
- Pricing: AI-detected secret alerts will remain included in GHSP and GHAS at no additional charge. The new opt-in checks for push protection and the security review command will consume GitHub AI Credits.

GitHub announced a new purpose-built model for detecting leaked secrets, which reads surrounding code to identify likely credentials including passwords without a recognizable token format. The model is being integrated into secret scanning alerts, push protection, and GitHub Copilot security reviews. AI-detected secret alerts remain included in GHSP and GHAS at no additional charge, while opt-in checks for push protection and the security review command will consume GitHub AI Credits.

## Evidence

Verbatim from https://github.blog/changelog/2026-10-07-purpose-built-model-for-leaked-secret-detection:

> With our new purpose-built model, we’re bringing context-aware detection into more developer workflows to help you catch secrets before they’re exposed.

---

Record: https://forck.live/items/16440-purpose-built-model-for-leaked-secret-detection
Catalogue: https://forck.live/llms.txt
Current issue: https://forck.live/feed.md
