GitButler's engineering blog says Git 3.0's plan to make SHA-256 the default hash algorithm is a mistake that will cost the ecosystem more than it saves.
GitButler, the company behind a Git desktop client, published a post arguing that Git's next major release, version 3.0, is wrong to flip the default object hash to SHA-256 for new repositories. The post, published October 1, 2026, doesn't take issue with SHA-256 itself - it objects to changing the default before the wider Git ecosystem, including hosting services, tooling, and existing repositories, is ready for it. The piece sparked a lively discussion thread, pulling 46 points and 29 comments within a day.
Git's SHA-1 to SHA-256 migration has been in the works since 2017, after researchers showed SHA-1 could be practically broken. But adoption outside Git's own test suite has crawled, because nearly every tool, remote, and integration still assumes SHA-1 object IDs. Flipping the default in 3.0 pushes that compatibility question onto every developer who starts a new repo, not just the maintainers who have spent years laying groundwork for the switch.
Git has floated this transition for the better part of a decade without touching a single default. Whether 3.0 is the moment that finally changes, or another false start, is hard to judge from one blog post and a comment thread.