| ▲ | orf 4 hours ago | |||||||
> The GPG signature is not signing the git hash, if that's what you mean. It kind of is - it’s signing the hash of the tree object, which is the actual thing that you’d attack with a hash collision | ||||||||
| ▲ | kazinator 4 hours ago | parent [-] | |||||||
I understand that if we sign a commit with the help of some arbitrarily strong hash, it doesn't protect the parent commit(s). The integrity of the SHA-1 hash references to the parent commits is not in question, but the authenticity of those commits themselves. | ||||||||
| ||||||||