API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-114 · Runtime, protocol & platform support

GitHub disables SHA-1 in HTTPS and TLS on 15 September 2026

GitHub scheduled a SHA-1 HTTPS brownout for 14 July 2026 and full disablement across github.com, GitHub Enterprise Cloud and partner CDNs on 15 September 2026.

GitHubSHA-1HTTPSTLSretirement

Previous state

Older browsers, API clients and Git HTTPS stacks could still negotiate configurations that depended on SHA-1.

Current state

SHA-1 is fully disabled for GitHub HTTPS/TLS and partner CDNs from 15 September 2026 after an 18-hour github.com brownout on 14 July.

Who needs to care

Browsers, Git clients and API integrations connecting to github.com, GitHub Enterprise Cloud or GitHub partner CDNs with legacy TLS support.

What to do

Upgrade browsers, Git, operating-system TLS libraries and API frameworks and verify connectivity against github.dev, where SHA-1 is already disabled.

What the source does not prove

GitHub Enterprise Server is explicitly excluded. The 14 July brownout did not apply to CDNs, while the 15 September full disablement does.

Lifecycle history

Dated event sequence

  1. Retirement schedule published

    GitHub announced the brownout and full-disable dates.

  2. github.com brownout

    SHA-1 was disabled from 00:00 to 18:00 UTC for github.com; CDNs were excluded.

  3. Full disablement

    SHA-1 is removed from GitHub HTTPS/TLS and partner CDNs.

Evidence ledger

First-party sources

  1. 01
    GitHub Changelog — Sunsetting SHA-1 in HTTPS on GitHub

    Official protocol-retirement changelog · 2026-04-20

    Open official source ↗