| ▲ | crote 6 hours ago | |||||||||||||||||||||||||||||||
That doesn't make a difference: with sha1 a malicious change in content will still result in the same content hash, so the signature will still be valid, and the commit hash will still be the same. | ||||||||||||||||||||||||||||||||
| ▲ | kazinator 6 hours ago | parent [-] | |||||||||||||||||||||||||||||||
Only if the GPG signing process stupidly relies on the SHA-1 hash. I.e. if it takes an unsigned commit and signs only its SHA-1 hash and then creates a new commit with GPG headers. If that's how it works, that is massively stupid and can be fixed without forcing SHA-256 as a git hash. Just have the signing calculate its own digest for its own purposes. That digest can be the SHA-256; since the infrastructure is there for it, signing should use SHA-256 regardless of what hash is used by the repository for identifying and linking content. | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||