Taylor Blau shared lightly edited notes from the Contributor's Summit, taken by several volunteers. The seven topics were the security mailing list and process, Git 3.0, documentation, Outreachy sponsorship, next steps for pluggable ODB, AI contribution policy and protocol v2 for pushes. Blau said the notes are meant to let people continue the discussions on the list.

On Git 3.0, Patrick Steinhardt said the blocker had been GitHub's lack of SHA-256 support. brian m. carlson said GitHub has shipped it experimentally, with general availability probably in November. Patrick said GitLab already has non-experimental support and that they are looking at spring next year for Git 3.0. libgit2 supports SHA-256 and JGit does not. Emily said Google will not fund SHA-256 support in JGit, and carlson said Bitbucket does not look likely to support it. Emily said Gitoxide may have funding.

On security, Toon Claes said the security list gets many reports from outside the community, probably from people using AI, and that many are unaddressed. He has been organizing the reports, and some patches have been sitting for months. Taylor said many reports still need triage to decide which matter. Emily asked whether releases are waiting for reports to stop, and Patrick noted that a release eventually has to be cut.

On protocol v2 for pushes, carlson said some customers have millions of refs, and one was unhappy about an 896 MB ref advertisement. He said much of the code already exists and needs wiring up. Peff said the project had been waiting for someone with a use case. On pluggable ODB, Patrick said most things work but commit-graph and MIDX do not yet, and that the plan is to add a repository extension in 2.57.

On AI, participants discussed the current SubmittingPatches wording, which ties the question to whether contributors can certify AI-generated output under the DCO. Emily said the policy lacks attribution and pointed to an Assisted-by trailer used in a recent submission. For Outreachy, Chris said they want three interns at $10k each. GitLab or GitHub sponsored in the past, neither did last year, and Git paid itself. Emily offered to ask Google's OSPO.

Todd Zullinger replied on the documentation toolchain. Fedora has built docs with Asciidoctor by default since 2020, and CentOS Stream and RHEL use AsciiDoc but could use Asciidoctor, which EPEL already maintains. He said Red Hat could also ship pre-built docs.