Security improvements for SSH
We’re removing several SSH algorithms, adding a new algorithm, and requiring larger RSA SSH keys to improve security. The changes are as follows: We’re removing the ability to use RSA keys using SHA-1 in SSH (i.e., the ssh-rsa signature type, including ssh-rsa-cert-v01@openssh.com certificates using SHA-1).
Read GitHub's release noteshttps://github.blog/changelog/2026-09-22-security-improvements-for-ssh
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Deprecation notice: All-platform CodeQL bundle
DeprecationObservabilityDeveloper tools
GitHub Enterprise adds credential inventory exports
UpdateSecurityPricingObservability
Manage the code coverage ruleset condition with the REST API
GAObservabilityDeveloper tools
Stage-only npm tokens for safer automation
UpdateGovernanceSecurityDeveloper tools
Code scanning AI Scan no longer requires CodeQL default setup
PreviewSecurityObservability
Enforce GitHub Advanced Security configurations
UpdateGovernanceSecurityObservability
AI Scan for pull request APIs in public preview
PreviewSecurityObservabilityDeveloper tools
npm extends recovery-code security holds to all accounts
UpdateSecurityObservability
Also shipped on Sep 22, 2026
OpenAI GPT-6 Sol and GPT-6 Luna are now generally available on Amazon Bedrock
GALLMsGovernanceSecurity
Claude Opus 5.5 launches with a 1M token context window and 128k output
GAAI agentsLLMsDeveloper tools
Fast mode research preview available for Claude Opus 5.5 on the Claude API
PreviewLLMsDeveloper tools
Claude API beta lets tools be defined inside mid-conversation system messages
BetaLLMsMCPData integration