Git 3.0 will make SHA-256 the new default content hashing algorithm and it will be an incomprehensibly expensive and ultimately valueless and avoidable global nightmare.
In a well-fleshed-out post, Scott Chacon shows how unneecessary Git 3.0’s move to replace SHA-1 with SHA-256 is.
But signing keys can be stolen, have to be updated, revoked etc. A secure hash is an elegant way to say “this repo contains what I want”