Git 3.0's SHA-256 Default: How to Audit Your Tooling Before It Breaks
Git 3.0 is expected to switch the default object format from SHA-1 to SHA-256, making commit hashes 64 hex characters instead of 40. The author shares a checklist: spin up a sandbox repo with git init --object-format=sha256 and hunt down hardcoded 40-character assumptions in CI scripts, regexes and database schemas.
- Git 2.29 allowed --object-format=sha256; 2.42 dropped the experimental label
- SHA-256 hashes are 64 hex chars instead of 40; abbreviated hashes stay short
- SHA-256 and SHA-1 repos cannot push/fetch directly between each other
- The audit found 7 hardcoded spots in about half a day
Read next
Software