# The Git List: front page

Stories chosen daily by an AI editor from git@vger.kernel.org.

## 2026-10-07

### Contributor's Summit notes cover Git 3.0, security reports, AI policy and funding

Taylor Blau posted notes from this year's Contributor's Summit so people who could not attend can follow up on the list. Topics included Git 3.0, the security list, pluggable ODB, AI contributions, documentation, Outreachy funding and protocol v2 for pushes.

Full story: https://gitlist.dev/s/24 (thread https://gitlist.dev/t/66477)

### Stale delta base cache entries can corrupt data after a pack is closed

Patrick Steinhardt posted a two-patch fix for a bug where the delta base cache is never purged when a packfile is closed. A new pack allocated at the same address can then hit stale entries. Review has focused on how reliable the regression test is.

Full story: https://gitlist.dev/s/25 (thread https://gitlist.dev/t/66443)

### Patrick Steinhardt moves alternates into the files object-database backend

Patrick Steinhardt posted a 13-patch series moving alternates into the "files" source backend. Karthik Nayak finds the changes good but asked why multiple sources per object database should go away. Patrick says the multi-source design caused conceptual and performance problems.

Full story: https://gitlist.dev/s/26 (thread https://gitlist.dev/t/66446)

### SHA-256 thread turns to the state of interoperability work and migration tooling

The thread on Scott Chacon's RFC for signed SHA-256 tree digests has moved to the readiness of the SHA-256 transition. brian m. carlson described his public interop branch and its gaps, and other participants questioned migration tooling and urgency.

Full story: https://gitlist.dev/s/27 (thread https://gitlist.dev/t/66444)

### packed-refs rewrite copies unchanged refs verbatim, cutting deletion time about 20%

Karthik Nayak's patch writes unchanged refs from the packed-refs snapshot with `fwrite()` instead of reformatting them with `fprintf()`. He reports a consistent roughly 20% speedup when deleting packed refs. A revised version was posted after review comments.

Full story: https://gitlist.dev/s/28 (thread https://gitlist.dev/t/66427)

### Hash-transition document links to hijacked shattered.io domain

Mae Eckert reported that the hash-function-transition document links to shattered.io, which is now a different site. D. Ben Knoble posted a patch linking to the last good Web Archive snapshot, and Junio C Hamano said he will queue it.

Full story: https://gitlist.dev/s/29 (thread https://gitlist.dev/t/66474)

### Julia Evans posts draft of a new beginner Git tutorial

Julia Evans sent a WIP series replacing gittutorial with a new beginner tutorial. It covers creating a repo and making commits, then pushing to a host such as GitHub or GitLab. No replies had arrived yet.

Full story: https://gitlist.dev/s/30 (thread https://gitlist.dev/t/66478)

## 2026-10-06

### Chacon's signed SHA-256 tree digest reopens the question of SHA-256 as the Git 3.0 default

Scott Chacon posted an RFC that would put a SHA-256 digest of a commit's tree into signed objects without a SHA-256 repository. Brian m. carlson and Patrick Steinhardt pushed back on the premise that the 3.0 default should be reconsidered.

Full story: https://gitlist.dev/s/16 (thread https://gitlist.dev/t/66444)

### Phillip Wood's series makes `git checkout -m` restore the original conflict labels

Phillip Wood proposed that the ort merge machinery write the labels to `.git/MERGE_LABELS` so `git checkout -m <path>` can reuse them. Junio Hamano suggested API tidy-ups; a side question about remembering conflict style drew objections from Johannes Sixt.

Full story: https://gitlist.dev/s/17 (thread https://gitlist.dev/t/66426)

### New merge-conflict manual page prompts questions about whether the code should change too

Julia Evans's seven-patch series adds a `gitmergeconflicts` page and links to it from conflict-producing commands. Junio Hamano asked whether conflict-marker labels and "deleted by us" wording should change; Evans said docs can drive code changes and shared a draft "ours and theirs" section.

Full story: https://gitlist.dev/s/18 (thread https://gitlist.dev/t/66387)

### Opt-in incremental connectivity check gets a design review from Patrick Steinhardt

Kristofer Karlsson's series adds `transfer.connectivityCheck=incremental`. Patrick Steinhardt said he would welcome a check that scales with changes, but questioned whether extra connectivity roots would help and asked for clearer documentation.

Full story: https://gitlist.dev/s/19 (thread https://gitlist.dev/t/66326)

### Report of ZIP timestamp and strict fast-import date bugs prompts a clamp-or-reject question

Matthew Luallen reported three date-handling bugs seen on Git 2.56.0. René Scharfe has been working through the ZIP behavior, asking whether anything actually uses the DOS timestamp and noting that clamping is possible.

Full story: https://gitlist.dev/s/20 (thread https://gitlist.dev/t/66464)

### Proposal for porcelain to share stashes through remotes meets resistance

Hanan Arshad's RFC proposed porcelain around `git stash export`/`import` for handing off stashes via a remote. Johannes Sixt and Junio Hamano said branches already do this; Arshad dropped `stash publish` but is considering a narrower proposal.

Full story: https://gitlist.dev/s/21 (thread https://gitlist.dev/t/66406)

### Patch to validate `fetch.followRemoteHEAD` lazily is down to minor fixes

Colin Hinton's patch stores the raw `fetch.followRemoteHEAD` string and validates it only where `do_fetch()` uses it. Junio Hamano sees two minor remaining issues; Matt Hunter commented on how the new state variables are interpreted.

Full story: https://gitlist.dev/s/22 (thread https://gitlist.dev/t/66363)

### Git for Windows 2.56.0(2) fixes GIT_CONFIG_GLOBAL=NUL regression

Johannes Schindelin announced Git for Windows 2.56.0(2). It bundles OpenSSL v3.5.9, adds a Git Credential Manager compatibility shim, and fixes `GIT_CONFIG_GLOBAL=NUL`, which had stopped working in 2.56.0.

Full story: https://gitlist.dev/s/23 (thread https://gitlist.dev/t/66468)
