4 ms·
> and the final commit being hashed with sha256 wouldn't matter. Git stores content, not diffs. So the signature verifies all content stored in that commit. It
by chimeracoder 4y ago
> and the final commit being hashed with sha256 wouldn't matter.
Git stores content, not diffs. So the signature verifies all content stored in that commit. It does t verify anything that came before it, unless those are specifically signed as well.
- ElectricalUnion 4y ago> Git stores content, not diffs. But the "contents" is just pointers to tree roots with a trusted hash. If the hash is no longer secure, you can't garantee that any such trees are your content, or safe.
- Arnavion 4y agoThe assumption in this context is that all those have been rehashed to SHA-256 too. The point was about whether that rehashing needed to be extended to previous commits.