"had gone from roughly 1 billion commits during all of 2025 to 2.9 billion commits in August 2026, an annualized pace of over 14 billion for the 2026 reporting year," GitHub COO Kyle Daigle said — a single sentence that understates how rapidly the software landscape is changing.
Commit growth and the expanding surface
GitHub's reported jump from roughly 1 billion commits in 2025 to 2.9 billion by August 2026 — and internal planning that moved from preparing for 10x scale to designing for 30x — frames a simple fact: vastly more code means vastly more credentials. The source material ties that volume directly to increased credential creation: more applications, integrations, automations, and agents create more identities that must authenticate. GitGuardian warns security teams that visibility must grow at the same pace.
The scale of exposed credentials
Concrete measurements illustrate the problem. GitGuardian detected 28.65 million new hardcoded secrets in public GitHub commits in 2025, a 34% year‑over‑year increase, and leakage tied to AI services rose 81%. Internal repositories were roughly six times more likely than public repositories to contain at least one secret, and about 28% of secrets incidents originated entirely outside source‑code repositories in collaboration and productivity systems. Public MCP configuration files alone held 24,008 unique secrets in 2025, of which 2,117 could be verified as valid.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDeveloper endpoints, agents, and infostealer campaigns
The credential layer follows credentials themselves — across repos, vaults, collaboration tools, and developer laptops. The end of 2025 saw new waves of infostealer attacks, named in the source as Shai‑Hulud and S1ingularity, that turned developer machines into supply‑chain entry points. GitGuardian's analysis of systems compromised during the Shai‑Hulud 2 campaign found 33,185 unique secrets across 6,943 compromised systems: 44% of those machines held more than 10 secrets and 5% contained more than 100.
That density matters because attackers are already exploiting credentials across managed and unmanaged environments. The 2026 Verizon Data Breach Investigations Report found compromised credentials accounted for 22% of initial access, and that corporate credentials on unmanaged devices drove a significant number of breaches. Separately, CrowdStrike reported an average eCrime breakout time of 29 minutes in 2025, with the fastest observed lateral movement occurring in 27 seconds — a reminder that discovery and response operate against machine speeds.
Detection needs richer context than a single finding
GitGuardian argues detection must produce more than coordinates. Validity, location, ownership, permissions, and dependencies are all necessary to convert findings into actionable inventory. On validity, the source notes that credentials tend to remain useful: secrets confirmed valid in 2022 were still valid 64% of the time when retested in January 2026. Location matters because the same credential appearing on a laptop and later in a public repo has a far different exposure history than one seen only in an internal repo. Fingerprinting that links multiple detections to a single credential produces a clearer picture of spread; ownership ties the finding to the team accountable for rotation or revocation; and permissions plus dependency mapping reveal what will break if a credential is changed.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: They must expand discovery beyond repository scanning to include endpoint discovery and public monitoring so inventories capture credentials that never entered central systems. Detection must be enriched with validity, ownership, permission, and dependency context before remediation or prevention can be reliable.
- Procurement leaders and affected enterprises: Vault coverage is only one denominator. Organizations with, for example, 50,000 credentials in approved vaults may still have thousands more in plaintext across repos and endpoints. Procurement decisions and vendor SLAs should account for coverage gaps the credential layer mapping exposes.
- End users and the general public: Developer machines and collaboration tools are now part of the enterprise attack surface. Infostealer malware and misconfigured agent access can expose credentials far beyond the original creator's intention, increasing the risk that long‑lived secrets remain exploitable years after they were issued.
Detection, GitGuardian recommends, is the foundational step: discover the population across repositories, public exposure, and developer endpoints; enrich each record with validity, ownership, permissions, and dependency data; then use that inventory to remediate and prevent. The math in the source is stark: secret exposure has grown 1.6 times faster than the developer population, and software production is accelerating toward a future some teams are designing for at 30x today's scale. That combination raises the cost of waiting — visibility must scale now or risk being outpaced by both agentic development and attackers moving at machine speed.
Source: The Hacker News — The Credential Layer Is Expanding Faster Than Security Teams Can See It




