Re: [RFC PATCH 0/4] sign a SHA-256 digest of the tree in commits and tags
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Oct 2, 2026, 15:52 UTC
- Message-ID
- <xmqqjyo0yu9b.fsf@gitster.g>
- In-Reply-To
- <20261002081846.25144-1-scott@gitbutler.net>
Scott Chacon <scott@gitbutler.net> writes:
Show 6 quoted lines
> I'm concerned about the ecosystem impact of moving the `git init` default > hashing function to SHA-256 in 3.0. I have suggested that it may be more > feasible with similar benefits to add the ability to inject an independently > calculated and verifiable tree content sha into signed objects instead. > > This RFC series is meant to demonstrate how this might work.
I have offered a few minor comments on the implementation, but those are conditional on the assumption that if this is a good idea, we would want these improvements. I have not yet formed an opinion on the overall direction.
Thanks.