Skip to content
Rush Commerce
Software & Dev3 min read

GitHub's AI secret detection model bills credits on every push

GitHub's new AI secret detection model finds passwords with no token format. AI push protection now uses AI Credits. Set a hard budget cap before you opt in.

GitHub shipped a purpose-built AI secret detection model on October 7. It reads the code around a string to decide if it is a credential, so it can catch a plain database password that no regex would flag. The detection is good news. The billing is the part to read twice: the new AI push protection check spends AI Credits on pushes, and those credits go on the organization's bill even when nothing gets blocked.

What actually happened

Per GitHub's changelog:

  • A fine-tuned model, not a chatbot. It only classifies likely credentials, including passwords with no recognizable token format. It does not write code or text.
  • Existing AI-detected alerts moved over automatically. Customers with AI-detected password alerts were switched to the new model on the announcement date. Those alerts stay included in GitHub Secret Protection (GHSP) and Advanced Security (GHAS) at no extra charge.
  • AI push protection is in private preview. It needs GitHub Team or Enterprise Cloud with GHSP or GHAS, and an admin has to turn it on.
  • /security-review gets secret checks soon. Private preview is "available soon" in the Copilot CLI and Copilot app. Individual Copilot plans are eligible and do not need GHSP.
  • Both new checks consume AI Credits. GitHub says usage starts "in the coming weeks." Push protection bills the repo's owning organization, even when the check doesn't block the push. /security-review bills the user's Copilot plan.
  • No accuracy numbers. The post gives no precision, recall, or false-positive rates.

Why it matters for your business

Leaked credentials are still one of the cheapest ways into a small company. The ones that worry us most never look like a "key." They look like DB_PASS = "summer2024!" in a config file. A model that reads context is the right tool for that. We want it on.

But a check that runs on every push is a metered line item now. A team with busy CI, a bot that commits often, or a coding agent pushing small fixes all day can spend credits without a single alert. And GitHub's own instructions say budget alerts do not stop usage. You have to tick Stop usage when budget limit is reached yourself.

What we'd do before opting in:

  1. Set a SKU budget first. Billing and licensing → Budgets and alerts → SKU-level budget → Advanced Security → Secret Protection AI Credits. Turn on the hard stop.
  2. Check who pushes the most. Agents and automation accounts are your biggest credit users. Know that number before the bill does.
  3. In the preview now? GitHub says continued use will start using credits. Disable it before that date if you haven't budgeted for it.
  4. Keep the free layer on. Regular secret scanning and AI-detected alerts cost nothing extra on GHSP. Turn those on everywhere.

Key takeaways

  • GitHub's new model detects passwords with no token format by reading surrounding code
  • AI-detected alerts stay included in GHSP and GHAS at no extra cost
  • AI push protection and Copilot /security-review checks will consume AI Credits
  • Push protection bills the org even when it doesn't block a push
  • Budget alerts don't cap spend: enable "Stop usage when budget limit is reached"

Not sure what your agents and CI are spending per push? We set up the guardrails: secret scanning, hard budget caps, and a pipeline that doesn't burn credits on every bot commit. See our services or run the numbers on your setup.

Sources: GitHub Changelog: Purpose-built model for leaked secret detection, GitHub Docs: Set up budgets.

  • #github
  • #secret-scanning
  • #push-protection
  • #ai-credits
  • #devsecops
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.