Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

Finding leaked passwords with AI: How we built Copilot secret scanning

Blog post from GitHub

Post Details
Company
Date Published
Author
Ashwin Mohan, Courtney Claessens
Word Count
1,725
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

Copilot secret scanning, a feature of GitHub Secret Protection, uses AI to enhance the detection of generic passwords in codebases, addressing the limitations of traditional regular expression methods. The development process involved overcoming challenges such as handling unconventional file types and optimizing AI models for precision and recall. The team implemented a mix of strategies, including various prompting techniques and resource management improvements, to refine the detection system and reduce false positives. By integrating a workload-aware request management system, they effectively balanced resource usage across different scanning tasks, resulting in a significant reduction in false positives. Following a successful private and public preview phase, which demonstrated a notable decrease in false positives and maintained detection accuracy, Copilot secret scanning is now available to all GitHub Secret Protection customers, contributing to enhanced application security.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Coding Assistant 17 835 112 56 +7%
LLM 13 4,855 541 180 +51%
Secrets Management 4 1,233 139 73 +105%
Reinforcement learning 1 217 54 34 +41%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.