Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

Finding leaked passwords with AI: How we built Copilot secret scanning

Blog post from GitHub

Post Details
Company
Date Published
Author
Ashwin Mohan, Courtney Claessens
Word Count
1,725
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

Copilot secret scanning, a feature of GitHub Secret Protection, uses AI to enhance the detection of generic passwords in codebases, addressing the limitations of traditional regular expression methods. The development process involved overcoming challenges such as handling unconventional file types and optimizing AI models for precision and recall. The team implemented a mix of strategies, including various prompting techniques and resource management improvements, to refine the detection system and reduce false positives. By integrating a workload-aware request management system, they effectively balanced resource usage across different scanning tasks, resulting in a significant reduction in false positives. Following a successful private and public preview phase, which demonstrated a notable decrease in false positives and maintained detection accuracy, Copilot secret scanning is now available to all GitHub Secret Protection customers, contributing to enhanced application security.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Coding Assistant 17 1,009 140 67 +17%
LLM 13 5,694 663 215 +42%
Secrets Management 4 1,334 167 87 +102%
Reinforcement learning 1 236 61 40 +31%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.