‹ BackHN Continuity

Thread

Looking forward to Git 2.56 – and 3.0

207 points · 116 comments · chmaynard

  1. KolmogorovComp · · focus · HN ↗
    Does it mean that when switching trop sha1 to sha256 you need to forcepush and rewrite all history? Wouldn’t that be a massive source of potential vulnerabilities?
    1. WorldMaker · · focus · HN ↗
      It is a giant format change, but in the current documentation [0] sounds more like a repack than a force-push. git keeps a lookup table of the SHA1 object ids similar to an index file and some interop is allowed between SHA1 repositories and SHA256. (Primarily if you still needed to use GitHub as an SHA1 server because of some support hiccup, but needed your local repo to be SHA256 for security or other reasons, that's partially/mostly supposted.) Objects need to be resigned with their SHA256 id, but for different reasons than rebase/force-push and with a subtly different developer experience. In theory using that compatibility index of SHA1 hashes a good UI could show both signatures.

      [0] Migration document: <a href="https:&#x2F;&#x2F;git-scm.com&#x2F;docs&#x2F;hash-function-transition" rel="nofollow">https:&#x2F;&#x2F;git-scm.com&#x2F;docs&#x2F;hash-function-transition

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.