git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: When should we release Git 3.0?

From
Michal Suchánek <msuchanek@suse.de>
Date
Oct 2, 2025, 16:10 UTC
Message-ID
<aN6j7giOosGreKUW@kitsune.suse.cz>
In-Reply-To
<xmqqfrc1xqsp.fsf@gitster.g>
On Thu, Oct 02, 2025 at 08:32:38AM -0700, Junio C Hamano wrote:
Show 21 quoted lines
> Patrick Steinhardt <ps@pks.im> writes:
> 
> > Once we have roadmaps, we should set a strict deadline that takes them
> > into account. Any hosting provider or implementation of Git that doesn't
> > provide a roadmap will not be taken into account in our planning.
> 
> Works fine as long as we assume everybody that matters will
> eventually want to move away from SHA-1.
> 
>  - If a stakeholder gives a roadmap that has no SHA-256 in their
>    future, in other words, if they are content to serve only the
>    SHA-1 projects, what's the impact to them?  We are not dropping
>    the support for SHA-1 in the sense that if you clone from an
>    existing SHA-1 repository you'll get an SHA-1 repository and you
>    can push and fetch between them just fine, so presumably that is
>    fine as well.
> 
>  - If a stakeholder gives a roadmap with SHA-256 so far into the
>    future that we cannot wait, what's the impact to them?  Their
>    customers that want SHA-256 earlier than they can supply could
>    move to other hosting or implementation, but not really.  Both

I suppose that's already the case to some extent. git does support sha256, some forges do as well, and some people want it to the point that they install such forge, and create the sha256 repositories although it is not the default.

There is some tradeoff here. When it's nice to have but not required people will use it when convenient. When it's really required people will use even an obscure implementation to get the requested feature.

Show 21 quoted lines
>    hosting providers and Git implementations have components that
>    are move than Git that are hard to migrate, like issue trackers,
>    CI services, workflow tools, etc., that make their customers
>    captive audience [*].
> 
>  - If a stakeholder has a roadmap with SHA-256 in line with our
>    timeframe, do we still need to assess the impact to them, or as
>    long as we and they work hard to stick to the plan, we all will
>    be happy?
> 
> > We should of course actively reach out to the projects that we're aware
> > of so that they have a chance to provide such a roadmap in the first
> > place.
> 
> 
> [Footnote]
> 
>  * Issue trackers and review logs that are federated, possibly using
>    Git database for storage and transfer, may allow projects and
>    users to freely roam across hosting sites, but there is no strong
>    incentive for the hosting sites to fund such an effort X-<.

Many forges provide migration options for importing data from other forges for which there is incentive, with various level of completeness and reliability. Another thing that contributes to lock-in is network effect of popular forges.

Thanks
Michal
Previous: Junio C HamanoNext: Patrick Steinhardt
Message 9 of 33 in “When should we release Git 3.0?”
  1. brian m. carlsonSep 30, 2025
  2. Luca MilanesioOct 1, 2025
  3. Taylor BlauOct 1, 2025
  4. rsbecker@nexbridge.comOct 1, 2025
  5. Taylor BlauOct 8, 2025
  6. rsbecker@nexbridge.comOct 8, 2025
  7. Patrick SteinhardtOct 2, 2025
  8. Junio C HamanoOct 2, 2025
  9. Michal SuchánekOct 2, 2025
  10. Patrick SteinhardtOct 7, 2025
  11. Michal SuchánekOct 7, 2025
  12. Patrick SteinhardtOct 7, 2025
  13. Michal SuchánekOct 7, 2025
  14. Junio C HamanoOct 7, 2025
  15. Michal SuchánekOct 7, 2025
  16. SZEDER GáborOct 8, 2025
  17. Patrick SteinhardtOct 9, 2025
  18. Ben KnobleOct 2, 2025
  19. Patrick SteinhardtOct 7, 2025
  20. rsbecker@nexbridge.comOct 7, 2025
  21. Taylor BlauOct 8, 2025
  22. Patrick SteinhardtOct 9, 2025
  23. brian m. carlsonOct 16, 2025
  24. Taylor BlauOct 8, 2025
  25. brian m. carlsonOct 16, 2025
  26. brian m. carlsonOct 2, 2025
  27. Taylor BlauOct 1, 2025
  28. Michal SuchánekOct 1, 2025
  29. brian m. carlsonOct 1, 2025
  30. Michal SuchánekOct 2, 2025
  31. Michal SuchánekOct 2, 2025
  32. Junio C HamanoOct 1, 2025
  33. brian m. carlsonOct 1, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.