3 ms·
It is an easy to overlook this, but even for someone in position of power to change, creating different code with the same hash is borderline impossible.
by asdfsa32 2mo ago
It is an easy to overlook this, but even for someone in position of power to change, creating different code with the same hash is borderline impossible.
- CBLT 2mo agoNon-sequitor? They're not providing a (sha-1) hash, they're providing source code to integration partners using their business channels, not public git providers. Those business channels include contracts etc to "secure their supply chain". You and I aren't in those business channels, and we're not being given anything with a hash. There's simply no hash to collide with?
- asdfsa32 2mo agoA git hash is cryptographically secure. It doesn't matter how you distribute it. That is the entire point you're missing.