It’s important for audit ability and security that people can’t change commit ids from under you. If you run a security review of commit A and decide it’s safe to automatically deploy on your production systems, you’re only doing that because you know commit A can’t be changed.