Remix.run Logo
▲ orf 4 hours ago

> The GPG signature is not signing the git hash, if that's what you mean.

It kind of is - it’s signing the hash of the tree object, which is the actual thing that you’d attack with a hash collision

▲kazinator 4 hours ago | parent [-]

I understand that if we sign a commit with the help of some arbitrarily strong hash, it doesn't protect the parent commit(s). The integrity of the SHA-1 hash references to the parent commits is not in question, but the authenticity of those commits themselves.

▲orf 4 hours ago | parent [-]

No, not the abstract tree formed by a series of commits.

The actual git ‘tree’ object, which is the thing a commit actually points to, referenced by a hash in the commit. That is signed by the GPG signature.