‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. bmacho · · focus · HN ↗
    I don't agree that SHA-1 is much longer feasible for git.

    But I also don't think that switching to SHA-256 must be painful. A git2->git3 converted repo could just store all the past hashes, so existing links don't break.

    1. Buttons840 · · focus · HN ↗
      I was thinking the same. Can't the git CLI see a hash and say "well, I don't see any matching SHA-256 hash, but let me check the Legacy SHA1 hashes I have stored", and still resolve an old SHA1 hash to the correct commit?
      1. hedora · · focus · HN ↗
        It could even do that + barf if it saw two objects with matching SHA-1 but mismatched SHA-256!
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.