GitHub Tames Secret Scans with LLMs
GitHub is using LLMs to slash false positives in secret scanning, boosting alert accuracy and developer efficiency by over 75%.

Visual TL;DR
too many alerts that look like secrets but aren't
From the article 3 mentionsGitHub is leveraging Large Language Models (LLMs) to make its secret scanning more trustworthy.
existing pipeline combining pattern and AI detection
From the article 3 mentionsThis enhancement builds upon GitHub's existing secret scanning pipeline, which combines pattern-based and AI-based detection.
From the article 4 mentionsTo combat this, GitHub partnered with Microsoft Security & AI to integrate more contextual reasoning into the verification process.
wasting time triaging false positive security alerts
From the article 4 mentionsThis friction erodes confidence in automated security systems.
examining how detected values are used within the code
From the articleThe new approach focuses on the verification step, adding LLM-based contextual analysis.
slashing false positives in secret scanning
over 75% improvement in focusing on genuine threats
From the article 4 mentionsThis focused context, rather than more raw code, is crucial for accuracy and efficiency.
© 2026 StartupHub.ai. All rights reserved. You may not republish this article in full without a license. Search engines and AI research tools may crawl and summarize for reference. Bulk reproduction or model training requires a license. See our terms.
Written by
Daniel SingerEditor, StartupHub.ai
Daniel Singer is the editor of StartupHub.ai, a technology expert and thought leader on AI and its applications across sectors, from fintech and healthcare to developer tooling and consumer software. He writes and tests the tools covered here thoroughly and regularly, and built StartupHub.ai to give founders, operators and buyers a clearer read on what they are actually being sold.