In a well-fleshed-out post, Scott Chacon shows how unneecessary Git 3.0's move to replace SHA-1 with SHA-256 is.

you are viewing a single comment's thread
view the rest of the comments
[–] 1 point 5 days ago

But signing keys can be stolen, have to be updated, revoked etc. A secure hash is an elegant way to say "this repo contains what I want"

  • source
  • parent