Git 3.0’s switch to SHA-256 might bring more pain than protection

Git 3.0 plans to make SHA-256 its default hash algorithm, but the switch might cause massive ecosystem headaches for almost no real security gain.
According to a post from GitButler, Git's upcoming 3.0 release introduces a breaking change that few developers are prepared for. Since 2005, Git has relied on SHA-1 to assign unique keys to commits and files. Researchers demonstrated theoretical collision attacks against SHA-1 in 2017, prompting Git maintainers to plan a default shift to SHA-256.
Why it matters: Changing the default hashing algorithm breaks compatibility across existing tools, scripts, and repositories. Accidental SHA-1 collisions are mathematically impossible in practice. You would need roughly 1.4 septillion random files in a single project to trigger one by chance. Even targeted attacks that replace an existing file with malicious code remain out of reach. The shift fixes a theoretical vulnerability while creating real-world friction.
Here's the gist: SHA-1 has cryptographic flaws, but your code isn't actually at risk.
Expect plenty of quiet anxiety to turn loud before Git 3.0 ships.
Sources
- Git 3.0 and SHA-256 — https://blog.gitbutler.com/git-3-sha-256
- Hacker News Discussion — https://news.ycombinator.com/item?id=49924179

