Hmm. If this is a security issue that matters, would you not be expected to migrate?
Not talking about archived code, but active projects that pre-date git 3.0
Not talking about archived code, but active projects that pre-date git 3.0
That way an old commit with a message having a sha1 can reference the archived version, and new commits reference the active version.