• Mihies@programming.dev
    link
    fedilink
    English
    arrow-up
    0
    arrow-down
    1
    ·
    4 days ago

    Submodules are not the preferred way to incorporate third-party code for any environment I know. And while web-exposed URLs for management tools like Jira or AzureDevOps will need to adapt before the new default can be used, doing so even with a wholesale re-hashing of every commit isn’t technically difficult.

    Well, like it or not, they are used. And not so rarely. Now, rehashing will probably work, but it will require every project to do that. If you use more than one submodule which is not under your control, you have again mixed hashes that you can’t fix easily.

    • DomeGuy@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 day ago

      Sorry for the late reply.

      Again, do you have any actual evidence that SHA-256 repositories in version 3.0 won’t be able to reference SHA-1 repositories as submodules?

      Based on the design doc it looks like git will include both hashes during the transition, specifically to allow two-way communication with SHA-1 remotes. You may not be able to include a random stranger’s SHA-1 submodule via a shallow clone, but just doing a full clone sure as heck looks like a supported usage.

      https://git-scm.com/docs/hash-function-transition