Open Source & Dev•August 9, 2026
GitHub Mandates Cryptographic Commit Signatures for Top 50,000 Open-Source Maintainers
To thwart software supply-chain poisoning, GitHub will reject unsigned git commits pushed to the primary branches of widely depended-upon npm, PyPI, and Cargo repositories.
Official Press Release
GitHubGitSupply ChainAppSecOpen Source
GitHub has announced that starting next month, all maintainers of repositories with more than 10,000 downstream dependents must cryptographically sign git commits using verified GPG, SSH, or Sigstore keys before pushing to default branches.
The move comes after multiple attempted supply-chain compromises in which attackers gained access to expired developer tokens and pushed malicious backdoors directly into release tags without review.
Subscribe for Updates
Get official press announcements and version releases sent directly to your email.