logoalt Hacker News

flowerthoughts • yesterday at 7:16 PM • 0 replies • view on HN

Oh, agreed this sounds like a terrible migration path and shouldn't really be needed in the first place.

What I'm missing in the article is whether any Git server accepts replacing a SHA-1 identified object it already has. If it doesn't, then the distribution trust discussed holds, and keeping SHA-1 seems fine. Adding additional signatures seems fine for those who need transitive trust.