(maint) Update GitHubSig to current GitHub RSA host key#277
Merged
Conversation
GitHub rotated its RSA SSH host key on 2023-03-24 after the prior private key was briefly exposed. The hard-coded GitHubSig still held the retired key, so appending it to a host's known_hosts collides with the key GitHub now presents, producing "REMOTE HOST IDENTIFICATION HAS CHANGED" and aborting ssh-based git clones (e.g. of private repos in pre-suites). Replace it with the current RSA host key (fingerprint SHA256:uNiVztksCsDhcc0u9e8BujQXVUpKZIDTMczCvj3tD2s, verified against GitHub's published value). Also drop the pinned IP 207.97.227.239 from the entry: GitHub serves SSH from many rotating addresses, so pinning one IP adds no security and risks further stale-entry mismatches. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
56065fe to
6da2e8e
Compare
beechtom
approved these changes
Jun 4, 2026
Contributor
Author
|
Confirmed this avoids the ugly warning: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
GitHubSigstill held GitHub's retired RSA SSH host key. GitHub rotated its RSA host key on 2023-03-24 (after the prior private key was briefly exposed), so appending the oldGitHubSigto a host'sknown_hostsnow collides with the key GitHub actually presents. SSH then refuses the connection with:which breaks ssh-based
git clones in pre-suites that rely onenable_git_https_access/GitHubSig(e.g. cloning private repos).Change
GitHubSigwith GitHub's current RSA host key. FingerprintSHA256:uNiVztksCsDhcc0u9e8BujQXVUpKZIDTMczCvj3tD2s, verified against GitHub's published SSH key fingerprints.207.97.227.239from the entry. GitHub serves SSH from many rotating addresses, so pinning a single IP provides no security benefit and risks further stale-entry mismatches.Verification
🤖 Generated with Claude Code