If you are a GitHub Enterprise Server customer, you will need to take action. GitHub announced that one of the keys compromised by the threat actor breach was a signing key.
https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/
