> There is no reason that a signing scheme must rely on and trust those hashes!
Not "must", but it would be stupid to use two sets of hashes without a compelling reason.
Two hashes are already used now: GPG isn't using a SHA-1 digest, but it's signing something that is using SHA-1 digests to refer to other objects.
(Inside GPG, there are configurable choices. It's possible to be using SHA-512, so in a SHA-256 git repo, you can still be using two hashes.)
Two hashes are already used now: GPG isn't using a SHA-1 digest, but it's signing something that is using SHA-1 digests to refer to other objects.
(Inside GPG, there are configurable choices. It's possible to be using SHA-512, so in a SHA-256 git repo, you can still be using two hashes.)