| ▲ | kazinator an hour ago | |
No, but, the hashes are features of the content tracking system that hook it together. There is no reason that a signing scheme must rely on and trust those hashes! We can round up the bits that make up a commit in a SHA-1-based repo, and sign those bits securely; this is a thing that is possible. | ||