The KeyGuardRail Brief
Confirmed updates

GitHub credential inventories and the next SSH changes

GitHub has added an enterprise credential inventory and announced changes to SSH authentication. The export is available now; the first SSH milestone is October 14. Check the scope before assigning work, and keep the unresolved retirement date separate from the confirmed milestones.

Credential ownership · Available on Enterprise Cloud

GitHub Enterprise adds credential inventory exports

Announced September 21, 2026. Sources checked September 28, 2026.

GitHub now offers a credential inventory through CSV export and a paginated API. It includes personal access tokens, app access and user SSH keys, with ownership and lifecycle fields where available. The export contains metadata, not token values.

Who it affects. Enterprise Cloud owners and people with the View enterprise credentials permission. GitHub App installations represent the ability to issue tokens, not every short-lived installation token. CSV rows can repeat a credential for each authorizing organization.

What remains uncertain. Enterprise Server support is announced for a future release without a version or date. An empty expiry field can mean unavailable or inapplicable data; it is not proof that a credential never expires. Inventory review and remediation remain separate tasks.

One next step. Ask the enterprise access owner to review an export, confirm who maintains each relevant credential, and assign follow-up for unknown expiry or ownership. Verify dependencies before changing access.

SSH authentication · Announced schedule

Check new RSA keys before October 14

Announced September 22, 2026. Sources checked September 28, 2026.

GitHub sets October 14, 2026 for the new RSA upload minimum, covering authentication and signing keys. It also schedules November 4 and December 9 brownouts for RSA/SHA-1 signatures and the diffie-hellman-group-exchange-sha256 key exchange.

Who it affects. Teams using Git over SSH on GitHub Cloud. HTTPS Git remotes are unaffected. Existing RSA keys can continue with clients that support RSA/SHA-2. The announcement places these restrictions in Enterprise Server 3.25 rather than applying the Cloud dates to every server.

What remains uncertain. The announcement lists January 13, 2026 for final removal, a date before its publication. We cannot confirm the intended final date and have not silently changed the year. The October milestone and two brownout dates are stated separately.

One next step. Have the repository or build-system owner check SSH client compatibility and new-key provisioning before October 14. GitHub recommends Ed25519 where supported; test any replacement before retiring a working key.

Related

Where to go next

Automation access: npm tokens, workflow policies, and an IoT TLS fix

Open the free inventory template

See how to get started