CARD · Card record
GitHub CLI’s old Linux signing key has expired
The old key for GitHub CLI’s official Linux repositories expired on September 5. APT/RPM setups configured before April 8 and left unchanged should verify the replacement key, including CI environments and older base images.
01
THE STORY · The original
Read the explanation and its limits.
Older setups using the official APT or RPM repositories should check that the replacement key is installed.
- Originalofficial statementhttps://github.blog/changelog/2026-09-03-github-cli-linux-package-signing-key-expires-september-5
Why it is worth understanding
If gh is installed from its official APT or RPM repository, check older servers, CI setups and base images for the new key. It may affect future installs or updates; the announcement provides distribution-specific checks and fixes.
Conditions and limitations
Not all GitHub CLI installations are affected: Windows, macOS, Homebrew and Conda are outside this change. Expiry does not mean every old client immediately fails; new signatures start with the first release after expiry. We have not checked reader environments.
Important additions and corrections
Dates below mark changes to our coverage.
- Addition ·
Clarified the expiry boundary: it does not immediately disable every old client; the signing change starts with the first new release after expiry.
- Addition ·
Added the signing-key expiry scope: focus on gh installations using the official APT/RPM repositories; other installation methods need separate consideration.
Reading progress is saved in this browser. Save or add a note →
02
THE THREAD · Full timeline
1 event, every row traceable.
A card accumulates records as its story develops: new corroborators, market contrasts, material changes at the original — each dated and linked to its archive day.
- Added to BitShovelEntered the BitShovel radar: first-party on GitHub Changelog (10 entries visible at collection).
03
SOURCES · Sources and evidence
Check each link's purpose and limits.
Sources and evidence · 3 links
Each link has a purpose and scope. Link counts do not establish independent confirmation; direct support applies only to the statements specified below.
- GitHub Changelog first-party postDirect support
Read the September 3 changelog and full official announcement in issue #13118 for September 5 expiry, the April 8 cutoff, affected repositories, excluded installation methods and the signing transition.
Limits: Past tense follows the announced date and the September 6 review date. We did not confirm that the first post-expiry release had shipped or modify any user machine.
- GitHub Changelog feedScope not documented
A per-link statement of support has not been attached.
- GitHub CLI's full official maintenance instructionsDirect support
Fingerprints, distribution-specific verification and update steps, and earlier announcement date.
Limits: Example errors are not observed incidents; these steps were not run locally.
Evidence for this assessment
https://github.com/cli/cli/issues/13118Retained evidence and full review record (JSON)
04
EDITORIAL REVIEW
Review of this card's wording and evidence.
Editorial review · Evidence reviewed
· Beijing time (UTC+8)
Reviewed official materials to clarify purpose, changes and usage conditions, distinguishing source descriptions from untested results. Original publication and observation dates are retained; an editorial revision is not a new product release.
This dates our review of the card's wording and evidence, not a project release or product update.