Git 3.0 will make SHA-256 the new default content hashing algorithm and it will be an incomprehensibly expensive and ultimately valueless and avoidable global nightmare.
In a well-fleshed-out post, Scott Chacon shows how unneecessary Git 3.0’s move to replace SHA-1 with SHA-256 is.
Wait, they don’t affect security? Wouldn’t a hash collision mean pulling that hash from GitHub would pull wrong code? Or maybe delete code? I’d assume the hash is used as a lookup key in a database somewhere.
You also pin dependencies to specific hashes for security reasons.
Wait, they don’t affect security? Wouldn’t a hash collision mean pulling that hash from GitHub would pull wrong code? Or maybe delete code? I’d assume the hash is used as a lookup key in a database somewhere.
You also pin dependencies to specific hashes for security reasons.
If you need security, you must sign the commits.