Would the author feel the same if git had used MD5 instead of SHA-1?
https://lore.kernel.org/git/Pine.LNX.4.58.0504291221250.1890...
As linked by another commenter in this thread, Linus worked out years ago that even if someone inserted a malicious object into the kernel repo, it would at best be a nuisance and not a major concern.
> We could be using MD5 and it would honestly probably be just fine.