Git 3.0's upcoming SHA-256 default will be a costly mistake
Summary
The article argues that Git 3.0's SHA-256 default will be costly and largely unnecessary, outlining potential tooling, workflow, and compatibility pains. It explains why hashing alone does not establish trust and discusses attack vectors, ultimately proposing independent tree hashing as a pragmatic alternative.