Making secret scanning more trustworthy: Reducing false positives at scale
Quick Answer
GitHub's collaboration with Microsoft Security & AI reduced false positives in secret scanning by 75.76%, enhancing developer trust and efficiency.
Quick Take
By integrating contextual reasoning into verification, GitHub improved alert accuracy while maintaining high detection performance across billions of pushes.
Key Points
- Achieved a 75.76% reduction in false positives, exceeding the 65% target.
- Integrated AI-based contextual reasoning to enhance secret scanning verification.
- Maintained high precision in detecting known secret formats at massive scale.
- Reduced developer time spent triaging alerts, allowing faster issue resolution.
- Focused context extraction improved alert quality without increasing data volume.
Source Excerpt
Alerts are more trustworthy and actionable when noise is reduced. See how we improved the verification step with context-aware reasoning.
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from GitHub AI & ML
See more →
Evaluating performance and efficiency of the GitHub Copilot agentic harness across models and tasks
The GitHub Copilot agentic harness demonstrates superior performance across various benchmarks, achieving leading token efficiency while offering flexibility with over 20 model options. This versatility allows developers to select the most suitable model for their tasks, enhancing productivity and effectiveness in coding.
