On Tue, Apr 29, 2008 at 5:46 AM, Jurko Gospodnetić
<jurko.gospodnetic@docte.hr> wrote:
Sorry for the confusion, its about using the signed tag and the SHA-1
of the parent commits, along with their associated trees and blobs to
verify the source and history. If you can't trust the signed tag, or
all of the SHA-1's, you can't trust the source and history.
However, as many said, I don't think there is any reason to not trust
SHA-1 is the context of source control.