ST-2026-114 · Runtime, protocol & platform support
GitHub disables SHA-1 in HTTPS and TLS on 15 September 2026
GitHub scheduled a SHA-1 HTTPS brownout for 14 July 2026 and full disablement across github.com, GitHub Enterprise Cloud and partner CDNs on 15 September 2026.
Previous state
Older browsers, API clients and Git HTTPS stacks could still negotiate configurations that depended on SHA-1.
Current state
SHA-1 is fully disabled for GitHub HTTPS/TLS and partner CDNs from 15 September 2026 after an 18-hour github.com brownout on 14 July.
Affected users
Who needs to care
Browsers, Git clients and API integrations connecting to github.com, GitHub Enterprise Cloud or GitHub partner CDNs with legacy TLS support.
Required response
What to do
Upgrade browsers, Git, operating-system TLS libraries and API frameworks and verify connectivity against github.dev, where SHA-1 is already disabled.
Evidence boundary
What the source does not prove
GitHub Enterprise Server is explicitly excluded. The 14 July brownout did not apply to CDNs, while the 15 September full disablement does.
Lifecycle history
Dated event sequence
- Retirement schedule published
GitHub announced the brownout and full-disable dates.
- github.com brownout
SHA-1 was disabled from 00:00 to 18:00 UTC for github.com; CDNs were excluded.
- Full disablement
SHA-1 is removed from GitHub HTTPS/TLS and partner CDNs.
Evidence ledger
First-party sources
- 01GitHub Changelog — Sunsetting SHA-1 in HTTPS on GitHub
Official protocol-retirement changelog · 2026-04-20
Open official source ↗