In a well-fleshed-out post, Scott Chacon shows how unneecessary Git 3.0's move to replace SHA-1 with SHA-256 is.

you are viewing a single comment's thread
view the rest of the comments
[–] 0 points 6 days ago* (1 child)

Wait, they don't affect security? Wouldn't a hash collision mean pulling that hash from GitHub would pull wrong code? Or maybe delete code? I'd assume the hash is used as a lookup key in a database somewhere.

You also pin dependencies to specific hashes for security reasons.

  • source
  • parent
  • hideshow 1 child comment