git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH 0/4] sign a SHA-256 digest of the tree in commits and tags

From
Junio C Hamano <gitster@pobox.com>
Date
Oct 2, 2026, 15:52 UTC
Message-ID
<xmqqjyo0yu9b.fsf@gitster.g>
In-Reply-To
<20261002081846.25144-1-scott@gitbutler.net>
Scott Chacon <scott@gitbutler.net> writes:
Show 6 quoted lines
> I'm concerned about the ecosystem impact of moving the `git init` default
> hashing function to SHA-256 in 3.0. I have suggested that it may be more 
> feasible with similar benefits to add the ability to inject an independently
> calculated and verifiable tree content sha into signed objects instead.
>
> This RFC series is meant to demonstrate how this might work.

I have offered a few minor comments on the implementation, but those are conditional on the assumption that if this is a good idea, we would want these improvements. I have not yet formed an opinion on the overall direction.

Thanks.
Previous: Scott ChaconNext: brian m. carlson
Message 8 of 22 in “sign a SHA-256 digest of the tree in commits and tags”
  1. 0/4 sign a SHA-256 digest of the tree in commits and tagsScott Chacon, Oct 2, 2026
  2. 1/4 tree-sha256: hash the contents of a tree with SHA-256Scott Chacon, Oct 2, 2026
  3. Junio C HamanoOct 2, 2026
  4. 2/4 tag: add --hash=sha256 to sign a tree-sha256 headerScott Chacon, Oct 2, 2026
  5. Junio C HamanoOct 2, 2026
  6. 3/4 commit: add --hash=sha256 to sign a tree-sha256 headerScott Chacon, Oct 2, 2026
  7. 4/4 gpg: add gpg.treeHash to sign a tree-sha256 header by defaultScott Chacon, Oct 2, 2026
  8. Junio C HamanoOct 2, 2026
  9. brian m. carlsonOct 2, 2026
  10. Scott ChaconOct 5, 2026
  11. Patrick SteinhardtOct 5, 2026
  12. Scott ChaconOct 5, 2026
  13. brian m. carlsonOct 5, 2026
  14. Johannes SchindelinOct 6, 2026
  15. Kristoffer HaugsbakkOct 6, 2026
  16. brian m. carlsonOct 6, 2026
  17. Junio C HamanoOct 6, 2026
  18. brian m. carlsonOct 6, 2026
  19. Christian CouderOct 6, 2026
  20. brian m. carlsonOct 6, 2026
  21. Christian CouderOct 7, 2026
  22. brian m. carlsonOct 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.