logoalt Hacker News

kazinator • yesterday at 8:13 PM • 2 replies • view on HN

The GPG signature is not signing the git hash, if that's what you mean.

The GPG signature signs some kind of hash calculated over the commit, minus the GPG header, which is thereby added.

The git hash is then calculated over the whole thing. The git hash is on the outside, and not part of the signing.


Replies

orf • yesterday at 10:28 PM

> The GPG signature is not signing the git hash, if that's what you mean.

It kind of is - it’s signing the hash of the tree object, which is the actual thing that you’d attack with a hash collision

➕ show 2 replies
crote • yesterday at 8:51 PM

That doesn't make a difference: with sha1 a malicious change in content will still result in the same content hash, so the signature will still be valid, and the commit hash will still be the same.

➕ show 1 reply