logoalt Hacker News

CBLTtoday at 3:22 AM1 replyview on HN

Non-sequitor? They're not providing a (sha-1) hash, they're providing source code to integration partners using their business channels, not public git providers. Those business channels include contracts etc to "secure their supply chain".

You and I aren't in those business channels, and we're not being given anything with a hash. There's simply no hash to collide with?


Replies

asdfsa32today at 7:03 AM

A git hash is cryptographically secure. It doesn't matter how you distribute it. That is the entire point you're missing.

show 1 reply