In short, git migrated to a hardened SHA-1 hash after the SHAttered [1] attack became known.
However, in the future more attacks against SHA-1 may be found, so git is trying to future-proof itself.
However, even in the case a hash function is no longer cryptographically secure, git doesn't lose out completely, just losing signing and shorthand fetches over the git protocol.
This project focuses on git with SHA256 and SHA-1 interchangeability, but doesn't address the git protocol side of things yet, which can come later.
[0] https://github.com/git/git/blob/master/Documentation/technic...
This is SHA-1:
hash = SHA1(input)
This is SHA-1DC in "only detect collision mode": collided, hash = SHA1DC(input)
Where "hash" for SHA1DC(input) will be the same value as SHA1(input), then there's the mode to work around such collisions: hash = SHA1DC_safe(input)
In this case "hash" will be the same as SHA1(input) in all cases, except those where the input is detected to be malicious (as in the SHAttered attack). Then SHA1DC_safe(input) will return a different ("safe") hash than SHA1(input) would.So depending on the mode you use it in it's a different hash function than SHA-1. The Git project only uses it in the "detect a collision and die" mode: https://github.com/git/git/blob/master/sha1dc_git.c#L17-L23
Here's the part of the code where you can see it's implementing a different hash function: https://github.com/git/git/blob/v2.19.0-rc0/sha1dc/sha1.c#L1...
I.e. if detect_coll and safe_hash are set, it will return different hashes than SHA1() for the same input.
[0] https://blog.github.com/2017-05-10-git-2-13-has-been-release...