Does it mean that when switching trop sha1 to sha256 you need to forcepush and rewrite all history? Wouldn’t that be a massive source of potential vulnerabilities?
Trusting a forced push w/o any other verification means nefarious history changes can be slipped in.
You can still verify the contents - the content blobs don’t change after the migration. Not sure if there’s a practical attack one could do but maybe
Um. how do you verify the contents? The history is for the contents you now have, not what might have been
Shallow clones and such would break but you could rehash the local history manually and compare the SHA256 hashes commit by commit, no?Issue is it would be pretty slow so you'd want it to be a one time thing.
KolmogorovComp · · focus · HN ↗
nomel · · focus · HN ↗
jayd16 · · focus · HN ↗
vlovich123 · · focus · HN ↗
awesome_dude · · focus · HN ↗
jayd16 · · focus · HN ↗
Issue is it would be pretty slow so you'd want it to be a one time thing.