API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-115 · SDKs, clients & toolchains

GitHub CLI Linux package repositories require a refreshed signing keyring

The current GitHub CLI Linux package-signing key expires on 5 September 2026; apt, yum and dnf users must rerun the distribution installation steps to obtain the replacement keyring.

GitHub CLILinuxPGPaptyumdnf

Previous state

Linux package repositories used the current gh signing key without the replacement keyring being installed on older configurations.

Current state

The published keyring contains both the current and replacement keys; affected package-manager installations must refresh it before the current key expires.

Who needs to care

GitHub CLI users installing or updating gh through apt, yum or dnf on Linux.

What to do

Rerun GitHub's current Linux installation steps for the relevant distribution before 5 September 2026 and update container build instructions where applicable.

What the source does not prove

Windows, macOS, Homebrew, Conda, source builds and precompiled binaries are explicitly unaffected. Users who already refreshed after 8 April need no further action.

Lifecycle history

Dated event sequence

  1. Replacement keyring published

    GitHub added the new signing key alongside the current key.

  2. Current key expires

    Unrefreshed apt, yum and dnf configurations risk package update disruption.

Evidence ledger

First-party sources

  1. 01
    GitHub Changelog — New PGP signing key for GitHub CLI Linux packages

    Official client-package signing announcement · 2026-04-08

    Open official source ↗