{"id":96242,"date":"2026-05-20T14:07:38","date_gmt":"2026-05-20T21:07:38","guid":{"rendered":"https:\/\/github.blog\/?p=96242"},"modified":"2026-05-26T15:49:08","modified_gmt":"2026-05-26T22:49:08","slug":"investigating-unauthorized-access-to-githubs-internal-repositories","status":"publish","type":"post","link":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/","title":{"rendered":"Investigation update: GitHub Enterprise Server signing key rotation"},"content":{"rendered":"<!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body><p class=\"wp-block-paragraph\"><strong>May 26, 2026<\/strong>: GitHub recently detected a cyber-attack and immediately activated our response process to investigate, disrupt malicious activity, mitigate the attack, and deny the threat actor further access. It&rsquo;s important to note that this investigation is still ongoing, and we will continue to provide details as appropriate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Given the reality of threat actors and the advent of AI technologies, we need to do all we can to protect our customers. Considering the repositories that have been attacked and an abundance of caution, we are rotating keys, including the GitHub Enterprise Server signing key. This key is used to sign binaries for GitHub Enterprise Server to validate GitHub as the source during a manually initiated update process. All binaries hosted by GitHub are valid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub Enterprise Server customers need to take immediate action as described below. No action is required for GitHub Enterprise Cloud.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-customers-need-to-do\">What customers need to do<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub Enterprise Server administrators will need to rotate the GPG public keys in their instance. Admins can follow these instructions to do so using a GitHub developed script to streamline the process. If you&rsquo;d like to independently verify the integrity of the script, its SHA256 digest is:<\/p>\n\n\n<div class=\"wp-block-code-wrapper\">\n<pre class=\"wp-block-code language-plaintext\"><code>3009bf5cdef034e153008cc375a05ac0bdbb1a2a325b22adb300c028e3766b43<\/code><\/pre>\n<clipboard-copy aria-label=\"Copy\" class=\"code-copy-btn\" data-copy-feedback=\"Copied!\" value=\"3009bf5cdef034e153008cc375a05ac0bdbb1a2a325b22adb300c028e3766b43\" tabindex=\"0\" role=\"button\"><svg aria-hidden=\"true\" height=\"16\" viewbox=\"0 0 16 16\" version=\"1.1\" width=\"16\" class=\"octicon octicon-copy js-clipboard-copy-icon\"><path d=\"M0 6.75C0 5.784.784 5 1.75 5h1.5a.75.75 0 0 1 0 1.5h-1.5a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-1.5a.75.75 0 0 1 1.5 0v1.5A1.75 1.75 0 0 1 9.25 16h-7.5A1.75 1.75 0 0 1 0 14.25Z\"><\/path><path d=\"M5 1.75C5 .784 5.784 0 6.75 0h7.5C15.216 0 16 .784 16 1.75v7.5A1.75 1.75 0 0 1 14.25 11h-7.5A1.75 1.75 0 0 1 5 9.25Zm1.75-.25a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-7.5a.25.25 0 0 0-.25-.25Z\"><\/path><\/svg><svg aria-hidden=\"true\" height=\"16\" viewbox=\"0 0 16 16\" version=\"1.1\" width=\"16\" class=\"octicon octicon-check js-clipboard-check-icon\"><path d=\"M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z\"><\/path><\/svg><\/clipboard-copy><\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>For single node topology<\/strong>, run these commands:<\/p>\n\n\n<div class=\"wp-block-code-wrapper\">\n<pre class=\"wp-block-code language-plaintext\"><code>$ curl -fsSL https:\/\/enterprise.github.com\/security\/2026-05-24\/rotate-gpg.sh -o rotate-gpg.sh   \n$ chmod ug+x .\/rotate-gpg.sh  \n$ .\/rotate-gpg.sh  \n$ sudo .\/rotate-gpg.sh <\/code><\/pre>\n<clipboard-copy aria-label=\"Copy\" class=\"code-copy-btn\" data-copy-feedback=\"Copied!\" value=\"$ curl -fsSL https:\/\/enterprise.github.com\/security\/2026-05-24\/rotate-gpg.sh -o rotate-gpg.sh   \n$ chmod ug+x .\/rotate-gpg.sh  \n$ .\/rotate-gpg.sh  \n$ sudo .\/rotate-gpg.sh\" tabindex=\"0\" role=\"button\"><svg aria-hidden=\"true\" height=\"16\" viewbox=\"0 0 16 16\" version=\"1.1\" width=\"16\" class=\"octicon octicon-copy js-clipboard-copy-icon\"><path d=\"M0 6.75C0 5.784.784 5 1.75 5h1.5a.75.75 0 0 1 0 1.5h-1.5a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-1.5a.75.75 0 0 1 1.5 0v1.5A1.75 1.75 0 0 1 9.25 16h-7.5A1.75 1.75 0 0 1 0 14.25Z\"><\/path><path d=\"M5 1.75C5 .784 5.784 0 6.75 0h7.5C15.216 0 16 .784 16 1.75v7.5A1.75 1.75 0 0 1 14.25 11h-7.5A1.75 1.75 0 0 1 5 9.25Zm1.75-.25a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-7.5a.25.25 0 0 0-.25-.25Z\"><\/path><\/svg><svg aria-hidden=\"true\" height=\"16\" viewbox=\"0 0 16 16\" version=\"1.1\" width=\"16\" class=\"octicon octicon-check js-clipboard-check-icon\"><path d=\"M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z\"><\/path><\/svg><\/clipboard-copy><\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>For HA or cluster topology<\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Log on to any node in your HA or cluster installation and run the following commands, they will download the script, copy it to all nodes and run it on all nodes:<\/li>\n<\/ul>\n\n\n<div class=\"wp-block-code-wrapper\">\n<pre class=\"wp-block-code language-plaintext\"><code>$ ghe-cluster-each -- curl -fsSL https:\/\/enterprise.github.com\/security\/2026-05-24\/rotate-gpg.sh -o rotate-gpg.sh  \n$ ghe-cluster-each -- chmod ug+x .\/rotate-gpg.sh   \n$ ghe-cluster-each -- .\/rotate-gpg.sh  \n$ ghe-cluster-each -- sudo .\/rotate-gpg.sh <\/code><\/pre>\n<clipboard-copy aria-label=\"Copy\" class=\"code-copy-btn\" data-copy-feedback=\"Copied!\" value=\"$ ghe-cluster-each -- curl -fsSL https:\/\/enterprise.github.com\/security\/2026-05-24\/rotate-gpg.sh -o rotate-gpg.sh  \n$ ghe-cluster-each -- chmod ug+x .\/rotate-gpg.sh   \n$ ghe-cluster-each -- .\/rotate-gpg.sh  \n$ ghe-cluster-each -- sudo .\/rotate-gpg.sh\" tabindex=\"0\" role=\"button\"><svg aria-hidden=\"true\" height=\"16\" viewbox=\"0 0 16 16\" version=\"1.1\" width=\"16\" class=\"octicon octicon-copy js-clipboard-copy-icon\"><path d=\"M0 6.75C0 5.784.784 5 1.75 5h1.5a.75.75 0 0 1 0 1.5h-1.5a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-1.5a.75.75 0 0 1 1.5 0v1.5A1.75 1.75 0 0 1 9.25 16h-7.5A1.75 1.75 0 0 1 0 14.25Z\"><\/path><path d=\"M5 1.75C5 .784 5.784 0 6.75 0h7.5C15.216 0 16 .784 16 1.75v7.5A1.75 1.75 0 0 1 14.25 11h-7.5A1.75 1.75 0 0 1 5 9.25Zm1.75-.25a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-7.5a.25.25 0 0 0-.25-.25Z\"><\/path><\/svg><svg aria-hidden=\"true\" height=\"16\" viewbox=\"0 0 16 16\" version=\"1.1\" width=\"16\" class=\"octicon octicon-check js-clipboard-check-icon\"><path d=\"M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z\"><\/path><\/svg><\/clipboard-copy><\/div>\n\n\n<ul class=\"wp-block-list\">\n<li>Note that the key is stored in both the admin and root accounts, so running a second time with sudo ensures that it is updated in both.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If the signing key is not rotated, future GitHub Enterprise Server version upgrades will fail verification with the following error message:&nbsp;<\/p>\n\n\n<div class=\"wp-block-code-wrapper\">\n<pre class=\"wp-block-code language-plaintext\"><code>Error: The file provided is not a valid GitHub Enterprise Server package.<\/code><\/pre>\n<clipboard-copy aria-label=\"Copy\" class=\"code-copy-btn\" data-copy-feedback=\"Copied!\" value=\"Error: The file provided is not a valid GitHub Enterprise Server package.\" tabindex=\"0\" role=\"button\"><svg aria-hidden=\"true\" height=\"16\" viewbox=\"0 0 16 16\" version=\"1.1\" width=\"16\" class=\"octicon octicon-copy js-clipboard-copy-icon\"><path d=\"M0 6.75C0 5.784.784 5 1.75 5h1.5a.75.75 0 0 1 0 1.5h-1.5a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-1.5a.75.75 0 0 1 1.5 0v1.5A1.75 1.75 0 0 1 9.25 16h-7.5A1.75 1.75 0 0 1 0 14.25Z\"><\/path><path d=\"M5 1.75C5 .784 5.784 0 6.75 0h7.5C15.216 0 16 .784 16 1.75v7.5A1.75 1.75 0 0 1 14.25 11h-7.5A1.75 1.75 0 0 1 5 9.25Zm1.75-.25a.25.25 0 0 0-.25.25v7.5c0 .138.112.25.25.25h7.5a.25.25 0 0 0 .25-.25v-7.5a.25.25 0 0 0-.25-.25Z\"><\/path><\/svg><svg aria-hidden=\"true\" height=\"16\" viewbox=\"0 0 16 16\" version=\"1.1\" width=\"16\" class=\"octicon octicon-check js-clipboard-check-icon\"><path d=\"M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z\"><\/path><\/svg><\/clipboard-copy><\/div>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-this-means-for-github-enterprise-server-customers\">What this means for GitHub Enterprise Server customers<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Future patches and releases will be signed with the new key, and customers will need to rotate to the new public key before those patches and releases can be installed. Customers should ensure they only download GHES updates from the official GitHub.com source URL. GitHub recommends that customers prepare to take GHES security updates at an increased rate over the coming months.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-looking-ahead\">Looking ahead<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As the information security landscape continues to evolve, we are prioritizing hardening our systems as new threats emerge. We&rsquo;ll continue to update our community on noteworthy developments. We remain committed not only to keeping GitHub secure but also to helping secure the broader open source ecosystem.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\">\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Original blog post, published May 20, 2026<\/strong>: On Monday May 18, we detected and contained a compromise of an employee device involving a <a href=\"https:\/\/github.com\/nrwl\/nx-console\/security\/advisories\/GHSA-c9j4-9m59-847w\">poisoned VS Code extension<\/a> published by a third party. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker&rsquo;s current claims of ~3,800 repositories are directionally consistent with our investigation so far.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We have no evidence of impact to customer information stored outside of GitHub&rsquo;s internal repositories, such as our customer&rsquo;s own enterprises, organizations, and repositories. Some of GitHub&rsquo;s internal repositories contain information from customers, for example, excerpts of support interactions. If any impact is discovered, we will notify customers via established incident response and notification channels.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We moved quickly to reduce risk. We rotated critical secrets Monday and into Tuesday with the highest-impact credentials prioritized first.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We continue to analyze logs, validate secret rotation, and monitor our infrastructure for any follow-on activity. We will take additional action as the investigation warrants.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We will publish a fuller report once the investigation is complete.<\/p>\n<\/body><\/html>\n","protected":false},"excerpt":{"rendered":"<p>GitHub Enterprise Server customers need to take immediate action.<\/p>\n","protected":false},"author":2278,"featured_media":93177,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_gh_post_show_toc":"yes","_gh_post_is_no_robots":"","_gh_post_is_featured":"no","_gh_post_is_excluded":"","_gh_post_is_unlisted":"","_gh_post_related_link_1":"","_gh_post_related_link_2":"","_gh_post_related_link_3":"","_gh_post_sq_img":"","_gh_post_sq_img_id":"","_gh_post_cta_title":"","_gh_post_cta_text":"","_gh_post_cta_link":"","_gh_post_cta_button":"","_gh_post_recirc_hide":"","_gh_post_recirc_col_1":"","_gh_post_recirc_col_2":"","_gh_post_recirc_col_3":"","_gh_post_recirc_col_4":"","_featured_video":"","_gh_post_additional_query_params":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"jetpack_post_was_ever_published":false,"_links_to":"","_links_to_target":""},"categories":[91],"tags":[],"coauthors":[2856],"class_list":["post-96242","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Investigation update: GitHub Enterprise Server signing key rotation - The GitHub Blog<\/title>\n<meta name=\"description\" content=\"GitHub Enterprise Server customers need to take immediate action.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Investigation update: GitHub Enterprise Server signing key rotation\" \/>\n<meta property=\"og:description\" content=\"GitHub Enterprise Server customers need to take immediate action.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/\" \/>\n<meta property=\"og:site_name\" content=\"The GitHub Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-20T21:07:38+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-26T22:49:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-blocks-github.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Alexis Wales\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alexis Wales\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/investigating-unauthorized-access-to-githubs-internal-repositories\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/investigating-unauthorized-access-to-githubs-internal-repositories\\\/\"},\"author\":{\"name\":\"Natalie Guevara\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/37273876e05b418f9e59da3267030711\"},\"headline\":\"Investigation update: GitHub Enterprise Server signing key rotation\",\"datePublished\":\"2026-05-20T21:07:38+00:00\",\"dateModified\":\"2026-05-26T22:49:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/investigating-unauthorized-access-to-githubs-internal-repositories\\\/\"},\"wordCount\":602,\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/investigating-unauthorized-access-to-githubs-internal-repositories\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/generic-security-logo-blocks-github.png?fit=1920%2C1080\",\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/investigating-unauthorized-access-to-githubs-internal-repositories\\\/\",\"url\":\"https:\\\/\\\/github.blog\\\/security\\\/investigating-unauthorized-access-to-githubs-internal-repositories\\\/\",\"name\":\"Investigation update: GitHub Enterprise Server signing key rotation - The GitHub Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/investigating-unauthorized-access-to-githubs-internal-repositories\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/investigating-unauthorized-access-to-githubs-internal-repositories\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/generic-security-logo-blocks-github.png?fit=1920%2C1080\",\"datePublished\":\"2026-05-20T21:07:38+00:00\",\"dateModified\":\"2026-05-26T22:49:08+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/37273876e05b418f9e59da3267030711\"},\"description\":\"GitHub Enterprise Server customers need to take immediate action.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/investigating-unauthorized-access-to-githubs-internal-repositories\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/github.blog\\\/security\\\/investigating-unauthorized-access-to-githubs-internal-repositories\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/investigating-unauthorized-access-to-githubs-internal-repositories\\\/#primaryimage\",\"url\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/generic-security-logo-blocks-github.png?fit=1920%2C1080\",\"contentUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/generic-security-logo-blocks-github.png?fit=1920%2C1080\",\"width\":1920,\"height\":1080,\"caption\":\"A grid of abstract cubes highlights a central cube displaying a shield with a checkmark to represent security.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/investigating-unauthorized-access-to-githubs-internal-repositories\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/github.blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/github.blog\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Investigation update: GitHub Enterprise Server signing key rotation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/github.blog\\\/#website\",\"url\":\"https:\\\/\\\/github.blog\\\/\",\"name\":\"The GitHub Blog\",\"description\":\"Updates, ideas, and inspiration from GitHub to help developers build and design software.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/github.blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/37273876e05b418f9e59da3267030711\",\"name\":\"Natalie Guevara\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d34214ae173f24fa973342259c80a7987a36de04c1edf4ab27385db6fe99a838?s=96&d=mm&r=gd9cd9e7ea5c1a52ff241c7cd2df20d97\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d34214ae173f24fa973342259c80a7987a36de04c1edf4ab27385db6fe99a838?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d34214ae173f24fa973342259c80a7987a36de04c1edf4ab27385db6fe99a838?s=96&d=mm&r=g\",\"caption\":\"Natalie Guevara\"},\"description\":\"Content Manager, GitHub Blog\",\"url\":\"https:\\\/\\\/github.blog\\\/author\\\/naguevara\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Investigation update: GitHub Enterprise Server signing key rotation - The GitHub Blog","description":"GitHub Enterprise Server customers need to take immediate action.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/","og_locale":"en_US","og_type":"article","og_title":"Investigation update: GitHub Enterprise Server signing key rotation","og_description":"GitHub Enterprise Server customers need to take immediate action.","og_url":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/","og_site_name":"The GitHub Blog","article_published_time":"2026-05-20T21:07:38+00:00","article_modified_time":"2026-05-26T22:49:08+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-blocks-github.png","type":"image\/png"}],"author":"Alexis Wales","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Alexis Wales","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/#article","isPartOf":{"@id":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/"},"author":{"name":"Natalie Guevara","@id":"https:\/\/github.blog\/#\/schema\/person\/37273876e05b418f9e59da3267030711"},"headline":"Investigation update: GitHub Enterprise Server signing key rotation","datePublished":"2026-05-20T21:07:38+00:00","dateModified":"2026-05-26T22:49:08+00:00","mainEntityOfPage":{"@id":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/"},"wordCount":602,"image":{"@id":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-blocks-github.png?fit=1920%2C1080","articleSection":["Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/","url":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/","name":"Investigation update: GitHub Enterprise Server signing key rotation - The GitHub Blog","isPartOf":{"@id":"https:\/\/github.blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/#primaryimage"},"image":{"@id":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-blocks-github.png?fit=1920%2C1080","datePublished":"2026-05-20T21:07:38+00:00","dateModified":"2026-05-26T22:49:08+00:00","author":{"@id":"https:\/\/github.blog\/#\/schema\/person\/37273876e05b418f9e59da3267030711"},"description":"GitHub Enterprise Server customers need to take immediate action.","breadcrumb":{"@id":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/#primaryimage","url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-blocks-github.png?fit=1920%2C1080","contentUrl":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-blocks-github.png?fit=1920%2C1080","width":1920,"height":1080,"caption":"A grid of abstract cubes highlights a central cube displaying a shield with a checkmark to represent security."},{"@type":"BreadcrumbList","@id":"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/github.blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/github.blog\/security\/"},{"@type":"ListItem","position":3,"name":"Investigation update: GitHub Enterprise Server signing key rotation"}]},{"@type":"WebSite","@id":"https:\/\/github.blog\/#website","url":"https:\/\/github.blog\/","name":"The GitHub Blog","description":"Updates, ideas, and inspiration from GitHub to help developers build and design software.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/github.blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/github.blog\/#\/schema\/person\/37273876e05b418f9e59da3267030711","name":"Natalie Guevara","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d34214ae173f24fa973342259c80a7987a36de04c1edf4ab27385db6fe99a838?s=96&d=mm&r=gd9cd9e7ea5c1a52ff241c7cd2df20d97","url":"https:\/\/secure.gravatar.com\/avatar\/d34214ae173f24fa973342259c80a7987a36de04c1edf4ab27385db6fe99a838?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d34214ae173f24fa973342259c80a7987a36de04c1edf4ab27385db6fe99a838?s=96&d=mm&r=g","caption":"Natalie Guevara"},"description":"Content Manager, GitHub Blog","url":"https:\/\/github.blog\/author\/naguevara\/"}]}},"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/pamS32-p2i","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-security-logo-blocks-github.png?fit=1920%2C1080","_links":{"self":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/96242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/users\/2278"}],"replies":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/comments?post=96242"}],"version-history":[{"count":5,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/96242\/revisions"}],"predecessor-version":[{"id":96334,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/96242\/revisions\/96334"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media\/93177"}],"wp:attachment":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media?parent=96242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/categories?post=96242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/tags?post=96242"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/coauthors?post=96242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}