‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. limonkufu · · focus · HN ↗
    It seems people are missing the point: it's not even the submodule incompatibility that's going to become an issue majorly (like python2 --> python3 but worse), the main issue is the loss of traceability for repos that changes in place (which I assume many will do). Imagine what will happen to these:

    - SLSA and Provenance or SBOM data in the supply chain security that uses commit hash. All the previous images are now pointing to a non-existing commit

    - All the documentation and tooling as the article calls out

    - All your traceability links from your project tool to your git repo, they will lose all the past data as it will be dead links

    So I hope there IS NOT a migration path for in-place replacement!

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.