logoalt Hacker News

kazinator • yesterday at 10:35 PM • 1 reply • view on HN

I understand that if we sign a commit with the help of some arbitrarily strong hash, it doesn't protect the parent commit(s). The integrity of the SHA-1 hash references to the parent commits is not in question, but the authenticity of those commits themselves.


Replies

orf • yesterday at 10:50 PM

No, not the abstract tree formed by a series of commits.

The actual git ‘tree’ object, which is the thing a commit actually points to, referenced by a hash in the commit. That is signed by the GPG signature.

➕ show 1 reply