In a well-fleshed-out post, Scott Chacon shows how unneecessary Git 3.0’s move to replace SHA-1 with SHA-256 is.

  • asdfasdfasdf@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 days ago

    Wait, they don’t affect security? Wouldn’t a hash collision mean pulling that hash from GitHub would pull wrong code? Or maybe delete code? I’d assume the hash is used as a lookup key in a database somewhere.

    You also pin dependencies to specific hashes for security reasons.