AI Agents Manus Parent Butterfly Effect Raises More Than $500 Million From Boyu and IDG in Its First Outside Funding Since Returning to Independence Video Generators CDN Veteran Wangsu Puts 300 Million Yuan Into Video Model Startup Sand.ai - a $960 Million Implied Valuation for a Company That Lost $21 Million Last Half Security AI Agents Now Write One in Three Pull Requests - GitHub Is Rebuilding Secret Protection Around That Fact News Oracle 1.3-Gigawatt Wisconsin Data Center Hits a Regulatory Wall: Transmission Review Reset to Zero, Full Power May Slip to 2029 Business SpaceX Seeks $40 Billion Led by Apollo to Bankroll a Massive Nvidia Chip Order - $10 Billion in Bank Loans Plus $30 Billion in Investment-Grade Debt News 18 Months in Prison for $8 Million in Fake Streams: First US Criminal Case Over an AI-Generated Music Catalog ChatGPT Common Sense Media Rates ChatGPT for Teens an Unacceptable Risk After 4,000 Test Prompts Produced Almost No Parent Alerts AI Agents Nous Research Confirms a $90 Million Series B at a $1.5 Billion Valuation - and Starts Selling Its Open Agent to Companies AI Agents Manus Parent Butterfly Effect Raises More Than $500 Million From Boyu and IDG in Its First Outside Funding Since Returning to Independence Video Generators CDN Veteran Wangsu Puts 300 Million Yuan Into Video Model Startup Sand.ai - a $960 Million Implied Valuation for a Company That Lost $21 Million Last Half Security AI Agents Now Write One in Three Pull Requests - GitHub Is Rebuilding Secret Protection Around That Fact News Oracle 1.3-Gigawatt Wisconsin Data Center Hits a Regulatory Wall: Transmission Review Reset to Zero, Full Power May Slip to 2029 Business SpaceX Seeks $40 Billion Led by Apollo to Bankroll a Massive Nvidia Chip Order - $10 Billion in Bank Loans Plus $30 Billion in Investment-Grade Debt News 18 Months in Prison for $8 Million in Fake Streams: First US Criminal Case Over an AI-Generated Music Catalog ChatGPT Common Sense Media Rates ChatGPT for Teens an Unacceptable Risk After 4,000 Test Prompts Produced Almost No Parent Alerts AI Agents Nous Research Confirms a $90 Million Series B at a $1.5 Billion Valuation - and Starts Selling Its Open Agent to Companies

AI Agents Now Write One in Three Pull Requests - GitHub Is Rebuilding Secret Protection Around That Fact

AI Agents Now Write One in Three Pull Requests - GitHub Is Rebuilding Secret Protection Around That Fact

GitHub says agents author a third of pull requests, up from under a tenth a year ago, and is deploying a fine-tuned ModernBERT classifier that reads surrounding code to catch unstructured secrets in under two milliseconds. The claim that it could more than double what push protection blocks is a GitHub claim, not independently verified.

GitHub has published new numbers on how much of the world's code is now written by machines - and rebuilt its leak defenses accordingly. AI agents are involved in roughly one in three pull requests on the platform, up from fewer than one in ten a year ago, the company said in a blog post this week alongside a changelog entry on a purpose-built detection model. At that trajectory, GitHub notes, most code pushed to the platform could be agent-written within two years.

The threat model follows directly. A new secret appears in publicly visible code about once every two seconds, a rate that has doubled annually for three years. In Q2 2026 alone GitHub screened 574 million pushes, 0.47 percent of which contained credentials. Push protection - the check that blocks a secret before it enters repository history - still catches only about 30 percent of newly detected secrets; the other 70 percent are found after the fact, where the mean time to manual revocation hovers around 40 days and roughly one in five takes more than 90.

The new tool is a fine-tuned ModernBERT classifier, built with Microsoft Applied Sciences, that assesses candidate secrets in context rather than by pattern matching. That means it can flag a password with no recognizable token format - a credential embedded in a database URL, a Kubernetes Secret manifest, a Dockerfile - while letting through placeholders like "changeme", and it evaluates candidate batches in under two milliseconds, fast enough to sit in the push critical path where slower LLM pipelines could not. GitHub says adding it to push protection could more than double the number of secrets prevented - a vendor claim, not an independently audited one.

The rollout is staged. Post-push AI-detected alerts switch to the new model starting today at no extra charge for Secret Protection and Advanced Security customers. AI checks in push protection are in private preview now, reaching organizations later this month, with usage billed through AI Credits. The classifier is also being added to the /security-review command in Copilot CLI and Copilot App, letting developers - and coding agents - scan for secrets before a push without an organization-level plan; those checks are opt-in and off by default. GitHub Enterprise Server 3.23 gets AI-detected alerts in public preview, covering air-gapped environments.

One finding cuts against the panic narrative: across nine quarters of data, screened pushes grew 2.84 times while pushes containing credentials grew 2.59 times - no statistically detectable rise in per-push leak rates - and the share of push-protection blocks that developers overrode fell from 6.63 percent to 3.93 percent. "Developers aren't becoming more careless; they're being outpaced," said Erin Havens, GitHub's product lead for secret scanning. GitHub's partner program, now covering more than 150 providers including OpenAI, Google Cloud, Slack and Hugging Face, auto-revokes many leaked tokens on notification - public scanning averaged 26 credential matches per second in Q2 2026.

The strategic point is bigger than one model. When agents commit code without a human in the loop, review-time vigilance stops being a control, and the push boundary becomes the last reliable checkpoint. GitHub calls the underlying tension its "four-body problem" - precision, latency, throughput and cost are coupled, and every protection decision spends developer attention. The bet is that a two-millisecond classifier is cheap enough to check everything, so that the people and the agents writing more software no longer need a proportional security team watching them do it.

Comments (0)

Log in to join the discussion

Log In

No comments yet