‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. thunderfork · · focus · HN ↗
    A lot of replies here seem to be asserting that this "isn't that hard" without addressing the thing that makes it most hard: submodule compatibility and the breadth of tooling
    1. pixl97 · · focus · HN ↗
      Submodules are a mistake.
      1. mort96 · · focus · HN ↗
        They're the best way we have to reference other repositories from one repository. All other solutions don't have the benefit of being built in to git and having support built in to all git forges.

        Ecosystems like Yocto are built around having meta layers as submodules. And, despite the usability flaws of submodules, it works really well.

        I also use submodules to include dependencies into C++ projects a lot. It works fine.

        1. bryanlarsen · · focus · HN ↗
          git subtree and git subrepo are compatible with all git forges and don't require normal developers to install the extensions. Only the person/bot doing the occasional sync to the external repo has to install the extension. I prefer git subrepo for most (but not all) use cases.
          1. pavon · · focus · HN ↗
            Note that subtree and subrepo have the same SHA-1/SHA-256 incompatibility issue that submodules do, so this will be just as much of a trainwreck for them as well.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.