Git 3.0's SHA-256 default is a costly mistake, says Chacon
Scott Chacon argues Git 3.0's plan to make SHA-256 the default hash for new repositories is a costly mistake: it breaks every existing 40-character SHA-1 identifier, and most Git libraries lack full SHA-256 support. He proposes embedding SHA-256 checksums in signed objects while keeping SHA-1 names. The Git project says the switch will wait until the ecosystem is ready, with no release date set.
- Chacon: no SHA-1 collision documented across billions of Git repos
- SHA-256 repos break URLs and references to 40-character hashes
- Alternative: SHA-256 checksums in signed objects alongside SHA-1
- Git will switch only when libraries and hosts are ready
Read next
Software