discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Secret protection must scale with software

GitHub's data shows that the number of pull requests involving AI agents has doubled in the past year, raising concerns about the carelessness of developers.

By Erin Havens·Oct 7·github.blog·2 min read

Intelligence analysis by Qwen 2.5 (3B)

Secret protection must scale with software
Image: github.blog

GitHub is seeing a significant increase in pull requests involving AI agents. This has led to concerns about developer carelessness, but the data suggests that developers are becoming more aware of the risks and are less willing to accept them.

Why it matters

As the number of pull requests involving AI agents continues to grow, the need for effective secret protection is becoming more critical to ensure the security of code.

GitHub is seeing more pull requests with AI agents. This has made some people worried that developers are becoming less careful. But the data shows that developers are becoming more aware of the risks and are less willing to accept them. To keep code safe, GitHub is working on better ways to stop secrets before they get into the code.

Analysis

Detection and Response

GitHub has seen a significant increase in the number of pull requests involving AI agents. This has led to concerns about developer carelessness, but the data suggests that developers are becoming more aware of the risks and are less willing to accept them. Over the past nine quarters, the number of screened pushes has grown 2.84 times while the number of pushes carrying credentials has grown 2.59 times. These figures challenge the common claim that agents are causing developers to become more careless. More pushes, no clear rise in push prevalence.

Prevention

GitHub has implemented push protection to prevent the introduction of unstructured secrets. The fine-tuned classifier they built with Microsoft Applied Sciences can assess a whole set of candidate secrets in less than two milliseconds and could more than double the number of secrets that they can prevent. Outpaced, not careless.

Remediation

GitHub's push protection stops about 30% of newly detected secrets before they enter repository history. The remaining 70% are already lost, and the cost of cleaning up a secret already lost to visible history is high. As the amount of code grows, the platform must take on the work of recognizing more of these secrets, earlier in development flows, to reduce the human effort required by those that remain.

Key points

  • GitHub has seen a significant increase in the number of pull requests involving AI agents.
  • The number of screened pushes has grown 2.84 times while the number of pushes carrying credentials has grown 2.59 times over the past nine quarters.
  • GitHub has implemented push protection to prevent the introduction of unstructured secrets.
  • GitHub's fine-tuned classifier can assess a whole set of candidate secrets in less than two milliseconds and could more than double the number of secrets that they can prevent.
  • GitHub's push protection stops about 30% of newly detected secrets before they enter repository history.
The Upside

As the number of pull requests involving AI agents continues to grow, GitHub will continue to improve its detection and response systems to prevent more exposures and reduce the human effort required by those that remain.

The Downside

If GitHub does not improve its detection and response systems, the volume of vulnerabilities introduced will become untenable, and the platform will struggle to keep up with the growing number of pull requests involving AI agents.

Originally reported at

github.blog

Discernion covers the story. Read the full piece at the source.

Tagsgithubopen-sourcesecurityaisecret-protection

Author

Erin Havens

Intelligence analysis by

Qwen 2.5 (3B)

Published

Oct 7, 2026

Source

github.blog

Share

Topics

githubopen-sourcesecurityaisecret-protection

Related

More from this desk

Steam Beta Now Defaults Non-Steam Windows Binaries To Using Proton

Oct 8·phoronix.com

Steam Beta Now Defaults Non-Steam Windows Binaries To Using Proton

Valve's new Steam client beta defaults to using Proton for non-Steam Windows binaries, improving Linux gaming experience.

Another Dozen Vulnerabilities Found In The X.Org Server & XWayland

Oct 7·phoronix.com

Another Dozen Vulnerabilities Found In The X.Org Server & XWayland

Twelve new security vulnerabilities have been discovered in the X.Org Server and XWayland, including use-after-free and buffer overflow issues. These affect versions prior to xorg-server-21.1.25 and xwayland-24.1.14.

keras-team/keras repository on GitHub
Oct 7·github.com

Keras 3 Unifies Deep Learning with Multi-Backend Support

Keras 3 is a new multi-backend deep learning framework supporting JAX, TensorFlow, PyTorch, and OpenVINO.

langgenius/dify repository on GitHub
Oct 7·github.com

Dify Unifies LLM App Development with Visual Workflows, RAG, and Autonomous Agents

Dify is an open-source platform designed to streamline the development of large language model applications, offering an intuitive interface for AI workflows, RAG pipelines, and agent capabilities.