- 259comments
- 16comments
- 34comments
- 69comments
- 227comments
- 278comments
- 168comments
- 123comments
- 1comments
- 38comments
- 7comments
- 27comments
- 43comments
- 1comments
- 25comments
- 4comments
- 158comments
- 408comments
- 46comments
- 3comments
- 16comments
- 181comments
- 40comments
- 29comments
- 1comments
- 107comments
- 3comments
- 242comments
- —discuss
- 4comments
`git add --resolved` is a wonderful idea, and definitely something I would start using.
Does it mean that when switching trop sha1 to sha256 you need to forcepush and rewrite all history? Wouldn’t that be a massive source of potential vulnerabilities?
I don't know much about this. How does that enable vulnerabilities exactly?
Trusting a forced push w/o any other verification means nefarious history changes can be slipped in.