Why choose SHA1 and not something that is collission-resistant like SHA256 or SHA3?
https://marc.info/?l=git&m=148787047422954
Most of that argument applies, but if it ever becomes a problem, we should be able to move to something like SHA256 fairly easily.