Length extension attacks are not an issue for git, because every object has two fields in its header, which is prepended to the object before hashing: the object type and the length in bytes.
Interesting. Anyway, since they're going through the pain of changing the hash function, why not using the latest standard? SHA3 has been standardized for some time now, and using SHA256 isn't any easier than using SHA3-256.
While SHA2 and SHA3 use very different algorithms, the purpose of the SHA standard stays the same. Or maybe I'm missing some official document from NIST saying otherwise that you could point me to?
GTP · · focus · HN ↗
cesarb · · focus · HN ↗
GTP · · focus · HN ↗
adastra22 · · focus · HN ↗
GTP · · focus · HN ↗