Find fixed-length Git object ID assumptions before SHA-256 repositories expose them
JavaScript
0
2 commits
updated Oct 2, 2026
Find the Git hash assumptions that will break when a repository uses SHA-256.

Run it from a Git repository with Node 20 or newer:
npx --yes github:Arthur031221/git-sha-ready
A five-line example:
const commit = git.revParse('HEAD');
const valid = /^[0-9a-f]{40}$/.test(commit);
if (!valid) throw new Error('bad commit');
console.log(commit.slice(0, 40));
// The scan points to the validator and fixed slice.
The CLI reports each supported pattern with its file, line, confidence, source text and a repair hint. It reads Git-tracked text files up to 1 MiB and does not execute them during a normal scan. The included fixture shows two findings. The readiness percentage is a triage indicator derived from finding counts, not a guarantee that a project works with SHA-256.
git-sha-ready path/to/repo
git-sha-ready --json > findings.json
git-sha-ready --fail-on-high
git-sha-ready --probe 'npm test'
--fail-on-high exits 2 when a high-confidence finding exists. --probe is opt-in: it copies tracked source and config files into a disposable SHA-256 Git repository, creates one local commit and runs the shell command there. It returns the command exit code, with a two-minute timeout. Use a trusted command: the shell runs it, and a build or test script may access the network. The temporary repository is deleted afterward. The probe does not copy ignored or untracked files, so install dependencies inside the probe command if needed.
| Rule | Pattern | Suggested repair |
|---|---|---|
| GIT001 | A 40-hex-only regular expression | Accept both supported full object ID lengths or query Git. |
| GIT002 | A length comparison to 40 near Git terms | Query git rev-parse --show-object-format. |
| GIT003 | A fixed 40-character slice near Git terms | Preserve the full ID or ask Git for an abbreviated ID. |
| GIT004 | Direct .git/objects access | Use Git plumbing commands. |
| GIT005 | A 20-byte array or buffer near Git terms | Size storage for the repository hash algorithm. |
Findings tagged review need context. A 40-character checksum unrelated to Git should not be changed. Suppress a known false positive with git-sha-ready: ignore on the same line. This scanner searches text patterns, so it can miss aliases, multiline expressions and other spellings; it does not prove runtime compatibility. The Git hash transition guide describes the format change and implementation guidance.
npm ci
npm test
node bin/git-sha-ready.js .
MIT licensed. See CONTRIBUTING.md.
JavaScript
100.0%
Find fixed-length Git object ID assumptions before SHA-256 repositories expose them
JavaScript
0
2 commits
updated Oct 2, 2026
Find the Git hash assumptions that will break when a repository uses SHA-256.

Run it from a Git repository with Node 20 or newer:
npx --yes github:Arthur031221/git-sha-ready
A five-line example:
const commit = git.revParse('HEAD');
const valid = /^[0-9a-f]{40}$/.test(commit);
if (!valid) throw new Error('bad commit');
console.log(commit.slice(0, 40));
// The scan points to the validator and fixed slice.
The CLI reports each supported pattern with its file, line, confidence, source text and a repair hint. It reads Git-tracked text files up to 1 MiB and does not execute them during a normal scan. The included fixture shows two findings. The readiness percentage is a triage indicator derived from finding counts, not a guarantee that a project works with SHA-256.
git-sha-ready path/to/repo
git-sha-ready --json > findings.json
git-sha-ready --fail-on-high
git-sha-ready --probe 'npm test'
--fail-on-high exits 2 when a high-confidence finding exists. --probe is opt-in: it copies tracked source and config files into a disposable SHA-256 Git repository, creates one local commit and runs the shell command there. It returns the command exit code, with a two-minute timeout. Use a trusted command: the shell runs it, and a build or test script may access the network. The temporary repository is deleted afterward. The probe does not copy ignored or untracked files, so install dependencies inside the probe command if needed.
| Rule | Pattern | Suggested repair |
|---|---|---|
| GIT001 | A 40-hex-only regular expression | Accept both supported full object ID lengths or query Git. |
| GIT002 | A length comparison to 40 near Git terms | Query git rev-parse --show-object-format. |
| GIT003 | A fixed 40-character slice near Git terms | Preserve the full ID or ask Git for an abbreviated ID. |
| GIT004 | Direct .git/objects access | Use Git plumbing commands. |
| GIT005 | A 20-byte array or buffer near Git terms | Size storage for the repository hash algorithm. |
Findings tagged review need context. A 40-character checksum unrelated to Git should not be changed. Suppress a known false positive with git-sha-ready: ignore on the same line. This scanner searches text patterns, so it can miss aliases, multiline expressions and other spellings; it does not prove runtime compatibility. The Git hash transition guide describes the format change and implementation guidance.
npm ci
npm test
node bin/git-sha-ready.js .
MIT licensed. See CONTRIBUTING.md.
JavaScript
100.0%