Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

We updated our RSA SSH host key

Blog post from GitHub

Post Details
Company
Date Published
Author
Mike Hanley
Word Count
700
Company Posts That Month
35
Language
English
Hacker News Points
-
Post removed?
No
Summary

On March 24, GitHub replaced its RSA SSH host key for Git operations as a precautionary step after discovering that the private key was inadvertently exposed in a public GitHub repository, though there was no indication of misuse or compromise of customer data. This change affects only RSA SSH Git operations, leaving web traffic and HTTPS operations unaffected, and requires users experiencing host key verification issues to update their known_hosts file accordingly. GitHub emphasized that the exposure was not due to a security breach but rather an accidental publication, and users employing ECDSA or Ed25519 keys remain unaffected. GitHub Actions users might encounter workflow disruptions if using certain configurations, prompting updates to the actions/checkout action. The announcement was made by Mike Hanley, GitHub's Chief Security Officer, who has a background in leading security initiatives at Duo Security and Cisco.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.