ST-2026-242 · Transition & enforcement
GitHub CLI Linux repositories transition to the replacement package-signing key
GitHub's current CLI Linux package-repository PGP key expires on 5 September 2026; beginning with the first release after that date, APT and RPM metadata and newly published RPM packages use only the replacement key.
Previous state
APT and RPM installations could trust repository material signed with the current GitHub CLI Linux package-repository key before its 5 September 2026 expiry.
Current state
Beginning with the first GitHub CLI release after the current key expires, APT and RPM repository metadata and newly published RPM packages are signed only with the replacement key.
Affected users
Who needs to care
GitHub CLI users and automation using the official APT or RPM repositories, particularly installations configured before 8 April 2026 that have not refreshed the repository keyring.
Required response
What to do
Verify that the replacement key is trusted and refresh pre-8-April APT or RPM setup before consuming the first post-expiry release; Windows, macOS, source builds, community package managers, direct .deb files and standalone archives are outside this change.
Evidence boundary
What the source does not prove
GitHub proves the current-key expiry and replacement-key-only signing boundary for the first release after that date. It does not establish a midnight cutover, affect the listed non-APT/RPM installation paths, or prove that a post-expiry release has already occurred at observation.
Lifecycle history
Dated event sequence
- Dual-key keyring available
Installations configured on or after this date use the keyring containing both current and replacement keys.
- Current signing key expires
The next GitHub CLI release after expiry will use only the replacement key for the stated repository material.
Evidence ledger
First-party sources
- 01GitHub — GitHub CLI Linux package signing key expires September 5
Official GitHub Changelog · 2026-09-03
Open official source ↗