Why did Git migrate from SHA-1 to SHA-256?
SHA-1 produces 160-bit hashes with a known collision weakness. After 30+ years, collision attacks became practical, posing a theoretical integrity risk for very large repositories. SHA-256 provides 256-bit output with no known practical collisions, offering decades of safety. Git's migration is gradual to avoid breaking existing workflows.
Answered in
Merkle Trees: How Git Detects Changes in MillisecondsGit hashes files into nested cryptographic trees to skip unchanged directories in one comparison, finding changes across millions of files faster than scanning.
Read the full analysisOther questions this article answers
More system design questions
- Why doesn't Google just run Dijkstra faster?
- What is a shortcut edge and when is it precomputed?
- How much space do shortcut edges take compared to the original graph?
- Can Contraction Hierarchies handle dynamic graphs like traffic or road closure?
- Why contract low-degree nodes first instead of high-degree ones?
- What is a CRDT and why does it matter for real-time collaboration?
- How do CRDTs handle concurrent edits without a central server referee?
- Why did Figma move from operational transforms to CRDTs?
Every answer on Crashtech is written by the editor of the article it comes from — never auto-summarised. Browse all answers or the System Design beat.