GitHub has disabled SHA-1 in HTTPS connections for github.com and partner content-delivery networks. The change also applies to GitHub Enterprise Cloud and GitHub Enterprise Cloud with Data Residency.

The retirement followed a previously announced schedule that set September 15, 2026, as the transition date. SHA-1 has long been considered unsuitable for modern cryptographic use because advances in collision attacks weaken its ability to provide trustworthy integrity guarantees.

GitHub Enterprise Server is not affected by this specific change. Organizations using self-hosted Enterprise Server installations therefore have a different migration and compatibility timeline from customers using GitHub’s hosted services.

The change may affect older clients, proxies, integrations or automation that still depend on SHA-1-based HTTPS certificates or related legacy configuration. Development and platform teams should review Git clients, build runners, API integrations and network appliances that connect to GitHub, particularly in older or tightly controlled environments.