On Thu, Mar 18, 2021 at 4:00 PM Bruce Momjian <bruce@momjian.us> wrote:
> Probably because later commits might collide with shorter hashes. When
> you are reporting a hash that only looks _backward_, this is not an
> issue.
Right, but it's extremely unlikely to happen by accident. I was
suggesting that there might be a security issue. I could fairly easily
make my git commit match a prefix intended to uniquely identify your
git commit if I set out to do so.
There are projects that might have to consider that possibility,
though perhaps we're not one of them.
--
Peter Geoghegan