Arthur031221/git-sha-ready

Find fixed-length Git object ID assumptions before SHA-256 repositories expose them

JavaScript

0

2 commits

updated Oct 2, 2026

See the code

See what people are saying

SourceMessageScoreDate

I built a CLI to find Git hash length assumptions before SHA-256 breaks them (r/SideProject)

I built git-sha-ready after noticing how easy it is to write a Git integration around a 40 character object ID. A SHA-256 repository produces 64 character IDs, so a validator or fixed slice can reject a valid commit or silently shorten it. The tool scans Git tracked text files and prints the exact…

1

Oct 2, 2026

README

git-sha-ready

Find the Git hash assumptions that will break when a repository uses SHA-256.

A scan showing a fixed 40-character Git object ID validator and its repair hint

Run it from a Git repository with Node 20 or newer:

npx --yes github:Arthur031221/git-sha-ready

A five-line example:

const commit = git.revParse('HEAD');
const valid = /^[0-9a-f]{40}$/.test(commit);
if (!valid) throw new Error('bad commit');
console.log(commit.slice(0, 40));
// The scan points to the validator and fixed slice.

The CLI reports each supported pattern with its file, line, confidence, source text and a repair hint. It reads Git-tracked text files up to 1 MiB and does not execute them during a normal scan. The included fixture shows two findings. The readiness percentage is a triage indicator derived from finding counts, not a guarantee that a project works with SHA-256.

git-sha-ready path/to/repo
git-sha-ready --json > findings.json
git-sha-ready --fail-on-high
git-sha-ready --probe 'npm test'

--fail-on-high exits 2 when a high-confidence finding exists. --probe is opt-in: it copies tracked source and config files into a disposable SHA-256 Git repository, creates one local commit and runs the shell command there. It returns the command exit code, with a two-minute timeout. Use a trusted command: the shell runs it, and a build or test script may access the network. The temporary repository is deleted afterward. The probe does not copy ignored or untracked files, so install dependencies inside the probe command if needed.

What the scanner checks

RulePatternSuggested repair
GIT001A 40-hex-only regular expressionAccept both supported full object ID lengths or query Git.
GIT002A length comparison to 40 near Git termsQuery git rev-parse --show-object-format.
GIT003A fixed 40-character slice near Git termsPreserve the full ID or ask Git for an abbreviated ID.
GIT004Direct .git/objects accessUse Git plumbing commands.
GIT005A 20-byte array or buffer near Git termsSize storage for the repository hash algorithm.

Findings tagged review need context. A 40-character checksum unrelated to Git should not be changed. Suppress a known false positive with git-sha-ready: ignore on the same line. This scanner searches text patterns, so it can miss aliases, multiline expressions and other spellings; it does not prove runtime compatibility. The Git hash transition guide describes the format change and implementation guidance.

Development

npm ci
npm test
node bin/git-sha-ready.js .

MIT licensed. See CONTRIBUTING.md.

cli
compatibility
developer-tools
git
sha256
static-analysis

Arthur031221/git-sha-ready

Find fixed-length Git object ID assumptions before SHA-256 repositories expose them

JavaScript

0

2 commits

updated Oct 2, 2026

See the code

See what people are saying

SourceMessageScoreDate

I built a CLI to find Git hash length assumptions before SHA-256 breaks them (r/SideProject)

I built git-sha-ready after noticing how easy it is to write a Git integration around a 40 character object ID. A SHA-256 repository produces 64 character IDs, so a validator or fixed slice can reject a valid commit or silently shorten it. The tool scans Git tracked text files and prints the exact…

1

Oct 2, 2026

README

git-sha-ready

Find the Git hash assumptions that will break when a repository uses SHA-256.

A scan showing a fixed 40-character Git object ID validator and its repair hint

Run it from a Git repository with Node 20 or newer:

npx --yes github:Arthur031221/git-sha-ready

A five-line example:

const commit = git.revParse('HEAD');
const valid = /^[0-9a-f]{40}$/.test(commit);
if (!valid) throw new Error('bad commit');
console.log(commit.slice(0, 40));
// The scan points to the validator and fixed slice.

The CLI reports each supported pattern with its file, line, confidence, source text and a repair hint. It reads Git-tracked text files up to 1 MiB and does not execute them during a normal scan. The included fixture shows two findings. The readiness percentage is a triage indicator derived from finding counts, not a guarantee that a project works with SHA-256.

git-sha-ready path/to/repo
git-sha-ready --json > findings.json
git-sha-ready --fail-on-high
git-sha-ready --probe 'npm test'

--fail-on-high exits 2 when a high-confidence finding exists. --probe is opt-in: it copies tracked source and config files into a disposable SHA-256 Git repository, creates one local commit and runs the shell command there. It returns the command exit code, with a two-minute timeout. Use a trusted command: the shell runs it, and a build or test script may access the network. The temporary repository is deleted afterward. The probe does not copy ignored or untracked files, so install dependencies inside the probe command if needed.

What the scanner checks

RulePatternSuggested repair
GIT001A 40-hex-only regular expressionAccept both supported full object ID lengths or query Git.
GIT002A length comparison to 40 near Git termsQuery git rev-parse --show-object-format.
GIT003A fixed 40-character slice near Git termsPreserve the full ID or ask Git for an abbreviated ID.
GIT004Direct .git/objects accessUse Git plumbing commands.
GIT005A 20-byte array or buffer near Git termsSize storage for the repository hash algorithm.

Findings tagged review need context. A 40-character checksum unrelated to Git should not be changed. Suppress a known false positive with git-sha-ready: ignore on the same line. This scanner searches text patterns, so it can miss aliases, multiline expressions and other spellings; it does not prove runtime compatibility. The Git hash transition guide describes the format change and implementation guidance.

Development

npm ci
npm test
node bin/git-sha-ready.js .

MIT licensed. See CONTRIBUTING.md.

cli
compatibility
developer-tools
git
sha256
static-analysis

Languages

JavaScript

100.0%