Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
bhhaskin
9y ago
0 comments
Share
The sha1 hash isn't used for security. You should be signing your commits if security is a concern.
0 comments
default
newest
oldest
nshepperd
9y ago
Uh, even a signed commit does still rely on the sha1 hash of the actual tree object and any parent commits. It won't stop something bad from happening if you fetch from a sha1 repo.
j
/
k
navigate · click thread line to collapse