Secret protection must scale with software
Blog post from GitHub
GitHub reports that AI agents are increasingly involved in code creation, with one in three pull requests now involving an agent, raising concerns that secret exposures could grow as development activity accelerates. Its data from Q2 2024 through Q2 2026 shows public pushes increased 2.84 times while pushes containing credentials rose 2.59 times, with no statistically detectable increase in the per-push rate of secret exposure; developer overrides of push-protection blocks also declined from 6.63% to 3.93%. However, a new secret still appears in public code about every two seconds, and manual revocation averages roughly 40 days, illustrating that remediation does not scale as easily as code production. GitHub’s existing secret-scanning partnerships detect and report exposed credentials to providers, while push protection blocks recognizable secrets before they enter repository history, preventing about 30% of newly detected secrets overall. To expand prevention to unstructured credentials, GitHub developed a ModernBERT-based classifier with Microsoft Applied Sciences that evaluates candidate secrets in context in under two milliseconds and is intended to more than double the number of secrets blocked; it is entering private preview for eligible Enterprise Cloud and Teams organizations, will update post-push AI secret detection, and is planned for GitHub Enterprise Server and Copilot security-review tools.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 13 | No monthly metrics for this publish month. | |||
| AI Coding Assistant | 3 | No monthly metrics for this publish month. | |||
| AI Agents | 1 | No monthly metrics for this publish month. | |||
| Kubernetes | 1 | No monthly metrics for this publish month. | |||
| LLM | 1 | No monthly metrics for this publish month. | |||
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.