If you trust the sha-256, you know the commits you have and their ancestors are not evil. So, the sha-1s for those commits can be trusted.
You should also check the mapping table's sha-256 hash, to know that it's not evil.
If you later get an evil commit trying to masquerade as one of those, Git will presumably notice that there are two commits with the same sha1 in the same repo, and bail loudly.