Git 3.0 set to make SHA-256 the default hash, replacing SHA-1
The upcoming Git 3.0 release will switch the default object hashing algorithm from SHA-1 to SHA-256, a change the author argues will disrupt workflows across the Git ecosystem. Git uses hashes as keys in its content-addressable object database, and the author notes that no accidental SHA-1 collision has ever occurred across the billions of commits, trees and files created in Git's 20-year history.
GoKawiil's interpretation of the reporting above, not reported fact.
The author argues this switch could force extensive, costly migration work across tooling, hosting platforms and repositories for what he characterizes as negligible practical security benefit, since real-world SHA-1 collisions in Git have not occurred. This framing suggests a broader tension between theoretical cryptographic risk and the real-world cost of infrastructure change, though the author's view represents one critical perspective rather than a consensus position.
- Git 3.0 is expected to make SHA-256 the default hashing algorithm instead of SHA-1.
- The author contends this change offers little practical benefit, as no accidental SHA-1 collisions have occurred in Git's history.
- The shift could impose significant migration costs and disruption across the global Git ecosystem, according to the author.
Source: blog.gitbutler.com — Scott Chacon, 2026-10-01
Published there as: “Git 3.0's upcoming SHA-256 default will be a costly mistake”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.