GitHub has disabled SHA-1 in HTTPS connections for github.com, partner CDNs, GitHub Enterprise Cloud and data-residency offerings. GitHub Enterprise Server is not affected by this deadline.

Quick answer

QuestionAnswer
Is Git dropping SHA-1 commit IDs?This announcement concerns HTTPS negotiation, not commit format.
Who may break?Old TLS stacks, proxies or appliances limited to SHA-1.
Is GHES affected?No, according to GitHub.

Why SHA-1 must go

SHA-1 no longer provides the expected collision resistance for certificate signatures. Modern browsers already moved on, but some enterprise tools and embedded systems retain old libraries.

Likely symptoms

A clone or download may fail during TLS negotiation before authentication. Errors commonly mention certificates, signatures or no shared algorithm. Changing a token will not fix it.

Where to investigate

Inventory CI runners, old container images, inspection proxies, appliances and unsupported operating systems. Test github.com and CDN access from each environment, then update TLS libraries and trust stores.

Do not bypass validation

Disabling HTTPS verification turns compatibility trouble into a security flaw. Updating the client or proxy is the correct fix. The cutoff is a reminder that a SaaS dependency includes the cryptographic stack on every machine calling it.