{
  "id": 12852933,
  "title": "Migrating Git repos to SHA-256",
  "url": "https://urgent.news/2026/10/08/migrating-git-repos-to-sha-256",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-08T10:00:39.000Z",
  "source": {
    "name": "Lobsters",
    "slug": "lobsters",
    "url": "https://exa.y2k.diy/garden/git-sha256/"
  },
  "original_language": "en",
  "account": "Git has introduced SHA-256 as its new object format since version 2.42. This format offers benefits, but migrating a repository to it can be challenging, especially when dealing with submodules. The documentation provides limited guidance on the process, and it is difficult to find clear instructions.\n\nWhen attempting to migrate a repository containing submodules, issues arise. SHA-1 submodule object IDs are padded with zeroes when added to a SHA-256 repository. There exists a command called \"--rewrite-submodules-from\" and \"--rewrite-submodules-to\" that allows for rewriting submodule object IDs from one hash algorithm to another. These commands require specifying names and file paths, with the \"from\" marks created by git fast-export and \"to\" marks created by git fast-import.\n\nThe process involves several steps. First, ensure the repository does not reference any commits that are no longer part of a current branch. Then, use git fast-export and git fast-import to rewrite the submodule object IDs. This can be done locally or directly on the Forgeho server. Once the migration is complete, delete the old repository and rename the new one to reflect the SHA-256 format. Update the Forgeho server to recognize the repo as SHA-256. Finally, configure the repository to display the SHA-256 badge in the web UI and run the site administration actions to complete the migration.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}