git/list[1] front-page[2] threads[3] people[4] search[5] about
 

verifying git file contents without checking out history?

From
MWMarc Weber <marco-oweber@gmx.de>
Date
Nov 19, 2012, 01:50 UTC
Message-ID
<1353287836-sup-270@nixos>
git clone --depth=20 $url; git checkout $hash

How to verify that I have the contents I think I have - given that I trust my local git executable?

Would it be enough to also store the git log --pretty=format:%T $hash value and check that only? %T is the root tree hash.

Does git checkout verify the file tree checksum when receiving all blob objects from a server? Then verifying that %T didn't change should be enough to enable me fetching sources and trust them without running git fsck which would fetch all history.

Marc Weber
Next: Junio C Hamano
Message 1 of 3 in “verifying git file contents without checking out history?”
  1. Marc WeberNov 19, 2012
  2. Junio C HamanoNov 19, 2012
  3. Marc WeberNov 19, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.