• Mihies@programming.dev
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 days ago

    The root problem is that there is no backward compatibility - you can’t mix the two. Why is that is beyond me.

    • DomeGuy@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 days ago

      I read that whole article, and aside from an unsourced statement that GitHub et al will need “new and distinct servers” exactly zero of that seemed to support the thesis that a SHA-256 default was going to be “expensive”.

      Submodules are not the preferred way to incorporate third-party code for any environment I know. And while web-exposed URLs for management tools like Jira or AzureDevOps will need to adapt before the new default can be used, doing so even with a wholesale re-hashing of every commit isn’t technically difficult.

      What would be terrible and dangerous would be if git 3.0 entirely dropped SHA-1 support. But just as you’re free to keep on using “master” instead of “main”, i expect that extant projects will still be supported until a version after every major project has converted to SHA-256 or what have you.