| ▲ | kazinator 4 hours ago | |
I understand that if we sign a commit with the help of some arbitrarily strong hash, it doesn't protect the parent commit(s). The integrity of the SHA-1 hash references to the parent commits is not in question, but the authenticity of those commits themselves. | ||
| ▲ | orf 4 hours ago | parent [-] | |
No, not the abstract tree formed by a series of commits. The actual git ‘tree’ object, which is the thing a commit actually points to, referenced by a hash in the commit. That is signed by the GPG signature. | ||