Security improvements for SSH
UpdateVerifiedAdded Sep 22, 2026
We’re removing several SSH algorithms, adding a new algorithm, and requiring larger RSA SSH keys to improve security. The changes are as follows: We’re removing the ability to use RSA keys using SHA-1 in SSH (i.e., the ssh-rsa signature type, including ssh-rsa-cert-v01@openssh.com certificates using SHA-1).
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Sep 22 | Deprecation notice: All-platform CodeQL bundle Deprecation | Deprecation |
| Sep 21 | GitHub Enterprise adds credential inventory exports Update | Update |
| Sep 18 | Manage the code coverage ruleset condition with the REST API GA | GA |
| Sep 18 | Stage-only npm tokens for safer automation Update | Update |
| Sep 16 | Code scanning AI Scan no longer requires CodeQL default setup Preview | Preview |
| Sep 15 | Enforce GitHub Advanced Security configurations Update | Update |
| Sep 10 | AI Scan for pull request APIs in public preview Preview | Preview |
| Sep 9 | npm extends recovery-code security holds to all accounts Update | Update |