+− THE DAILY DIFFdev & AI news
NEEDS REVIEW

Git’s New Hash Default – What It Means

Git's proposed SHA-256 default creates a compatibility boundary for new repositories.

Git's proposed SHA-256 default creates a compatibility boundary for new repositories. We check the official plan, Scott Chacon's objection and a working GitHub preview exception, then cover Pi 1.0 and SvelteKit 3. Verdict: NEEDS REVIEW.

Read the written edition (English) ↗

What this video covers

  • Why can two Git repositories refuse to talk?
  • What does Git 3 actually change?
  • Why replace SHA-1 if Git detects collisions?
  • What did our local compatibility check show?
  • What survives a crash in Pi Durable?

Transcript

Why can two Git repositories refuse to talk?

0:00 You'd think upgrading Git keeps your tools talking. Git's planned new hash default creates repositories that today's old format can't talk to. In this video, why change? What breaks? Who is ready? There's already a working exception on GitHub. I'll show you what it proves at the end. It's Friday, October second, and this is The Daily Diff.

0:18 On Thursday, a GitHub cofounder called Git's planned change a costly mistake. Pi shipped a new agent harness, and SvelteKit shipped another migration. Scott Chacon helped build GitHub and wrote Pro Git, so this complaint comes from inside the house. The house also sells Git tools. First, the actual plan.

What does Git 3 actually change?

0:35 Git three would default new repositories to SHA two fifty six, once libraries and hosting services are ready to support it. The official document gives no release date and keeps SHA one supported. Your existing repository doesn't magically change format when you upgrade the executable. That's worth remembering before your group chat schedules an emergency migration. The drama is a proposed default, and the deadline is currently a blank calendar.

Why replace SHA-1 if Git detects collisions?

0:58 Why change at all? Git names objects by hashing their contents. Files feed into trees, and commits refer to trees and earlier commits. That gives you integrity across the history. Change the hashing scheme and object names change too, including the references stored inside other objects. Chacon reaches back to Linus Torvalds, Git's creator, arguing that trusted

1:17 distribution matters. That's a historical position, and Linus chose SHA one back in two thousand five. The security case has moved since then. Researchers demonstrated SHA one collisions in twenty seventeen, and later demonstrated a chosen prefix attack against PGP identity certificates. Modern Git detects known collision attacks with hardened SHA one. Its maintainers want protection against future attacks too, which is a reasonable thing to want from signatures.

1:41 Chacon thinks the ecosystem bill buys too little security. He proposes signing a separate strong checksum of tree contents, while keeping today's object addressing underneath. What breaks? I created both formats locally and hashed the same little file.

What did our local compatibility check show?

1:54 One object name has forty hex characters, the other has sixty four. Then I tried fetching between them. My installed Git rejected it with mismatched algorithms, exactly the compatibility gap described in the current official manual. This used my old installed Git, so it tells us about today's boundary. Calling it a test of the unreleased Git three would be creative accounting. The migration work reaches into scripts that assume a hash's length, and systems that link to object names.

2:19 Rehashing a history needs a mapping between those identities. Git's transition design includes that mapping and signature handling. Implementation readiness matters, because a design document doesn't upgrade the library hiding inside your favorite developer tool. That's the human cost in Chacon's argument. Every tool maintainer gets another compatibility job, while users discover that their version control now needs version control. For now, test your host and tooling before choosing the new format for a

2:44 project. Existing teams can keep their current format while that ecosystem catches up. Meanwhile, Pi reached one point zero.

What survives a crash in Pi Durable?

2:51 It's a coding agent harness from Earendil, with native MCP support through Codemode and tools loaded when they're needed. The team calls minimalism the point. If your agent setup already resembles a small government, keeping tools out of the prompt until needed sounds like administrative reform. It also released Pi Durable, a separate experimental framework. Tasks save checkpoints so a restarted process can pick up unfinished work from persistent storage. The crucial detail is tool replay.

3:16 A tool interrupted by a crash reruns only when it declares that safe. Otherwise the model gets told it was interrupted. That's a useful boundary when a tool can spend money. I want the assistant to remember my shopping list without celebrating a crash by buying it twice.

What does SvelteKit 3 migrate for you?

3:30 SvelteKit three also landed on Thursday, moving configuration into Vite and replacing dollar lib with hash lib, using standard package subpath imports. The migration command rewrites what it can and leaves a to do list for the rest. Your robot can help, and your diff still deserves reading. The announcement even recruits your robot friends for the leftovers. We're reaching the point where a framework upgrade ships homework and a suggested substitute teacher. And remote functions still need experimental Async Svelte.

3:56 A major version number feels reassuring, but individual features carry their own maturity labels. Check the ones you're actually using.

What does GitHub's working exception prove?

4:03 So who is ready for Git's new format? Here's that exception. A public GitHub repository containing Brian Carlson's talk already returns a full SHA two fifty six object name. I checked the public remote directly. The talk slides call support a private preview and say repository creation is still coming. There's actual progress behind the waiting room. That proves GitHub can serve this preview repository.

4:24 It gives us zero guarantee that ordinary project creation or all your integrations are ready. The exception has a permission boundary. If you'd rather read this than hear me say it, the diff lands in your inbox every morning, free at the daily diff dot dev, link below. So today's verdict is needs review.

Why does my verdict depend on the whole toolchain?

4:40 I'd keep the stronger hash option, and test the whole toolchain before changing defaults. Compatibility is part of shipping the security improvement. And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.

Sources

  1. Chaconblog.gitbutler.com
  2. Git's official plangit-scm.com
  3. Current interoperabilitygit-scm.com
  4. Transition designgit-scm.com
  5. Independent collision researchsha-mbles.github.io
  6. GitHub preview repositorygithub.com
  7. Pi 1.0earendil.com
  8. Pi Durableearendil.com
  9. SvelteKit 3svelte.dev
  10. HN discussionnews.ycombinator.com

Related videos