Hacker News new | ask | show | jobs
by faangsticle 1086 days ago
Of course it will, since you'll either get the commit you wanted at the time you wrote the script, or an error.
1 comments

Unless someone is very good at finding SHA1 collisions.
The collisions need to deliver malicious payload as well, making it extra hard
Those are still very hard to get for a random hash, and GitHub I think warns (or blocks?) you if you try to push a hash with a known vulnerability.