GitHub CLI Linux package signing key expires September 5, 2026
securityengineer
breaking patch
The PGP signing key for GitHub CLI's Linux APT and RPM package repositories will expire on September 5, 2026. After this date, new packages and repository metadata will be signed exclusively with a replacement key. Users who installed `gh` from official repositories before April 8, 2026, or manage installations via custom images, must verify their system trusts the replacement key to avoid update interruptions. A keyring containing both the old and new keys was published in April to facilitate this transition.
Maintenance (1) ›
- Build from source
Read the original announcement →
https://github.blog/changelog/2026-09-03-github-cli-linux-package-signing-key-expires-september-5
Related releases
- GitHub Actions Adds New API, Permissions, and Workflow Context Properties GitHub Changelog ·
- npm adds multiple trusted publishing configurations, improves security for staged releases GitHub Changelog ·
- GitHub Copilot to Deprecate Selected AI Models by October 2026 GitHub Changelog ·
- Gemini 3.8 Flash Now Available in GitHub Copilot GitHub Changelog ·
- GitHub Reopens Copilot Business & Enterprise Sign-ups with Billing Updates GitHub Changelog ·
- CodeQL 2.26.4 Enhances GitHub Actions Security Detections and Language Support GitHub Changelog ·