Does it mean that when switching trop sha1 to sha256 you need to forcepush and rewrite all history? Wouldn’t that be a massive source of potential vulnerabilities?
Trusting a forced push w/o any other verification means nefarious history changes can be slipped in.
Semi-relevant-ish: <a href="https://blog.citp.princeton.edu/2013/10/09/the-linux-backdoor-attempt-of-2003/" rel="nofollow">https://blog.citp.princeton.edu/2013/10/09/the-linux-backdoo...
KolmogorovComp · · focus · HN ↗
nomel · · focus · HN ↗
jayd16 · · focus · HN ↗
wtfwhateven · · focus · HN ↗