The private bits are all in the same place: if one is compromised, so are the rest.
The private bits are all in the same place: if one is compromised, so are the rest.
Curious though that the compliance rules are strict enough it warrants distinct keypairs, but not that strict for the devs to use dedicated hardware.
If you have a GitHub Enterprise user for internal code development, that GitHub Enterprise user is restricted from interacting outside of the GitHub Enterprise/ If you also need to contribute to OSS projects as part of your job, you have to use a different GitHub user, and therefore a different keypair.
However if you're worried about this then you should probably be using a hardware token anyway - something that supports SSH authentication via FIDO2, GPG, or smart card interface.
Your signing key for personal projects probably has a different temporality.
What does this achieve exactly?