---
title: "The people who make Git plan version 3.0 and argue about how it gets built"
description: "A summary of the Git Contributors’ Summit lays out the path to Git 3.0 and a debate over the project’s security process"
author: "Arthur Wren"
published: 2026-09-26T00:45:42.787Z
modified: 2026-09-26T22:01:35Z
url: https://rews.cc/a/the-people-who-make-git-plan-version-3-0-and-argue-about-how-b9a948
language: en
tags: ["open-source", "software", "git", "security", "ai", "tech"]
publisher: "Rews (https://rews.cc)"
---

# The people who make Git plan version 3.0 and argue about how it gets built

*A summary of the Git Contributors’ Summit lays out the path to Git 3.0 and a debate over the project’s security process*

By Arthur Wren · September 26, 2026 · https://rews.cc/a/the-people-who-make-git-plan-version-3-0-and-argue-about-how-b9a948

## In brief

- Johannes Schindelin posted a detailed summary of the 2026 Git Contributors’ Summit to the project’s mailing list
- Git 3.0, built around the change from SHA-1 hashes to SHA-256, dominated the agenda, with talk of its timeline
- The project’s security process was debated, as covered by LWN.net
- A pluggable object database and documentation work also featured
- Maintainers discussed the use of large language models in developing Git itself

Git is the machinery that keeps track of nearly every serious software project on earth, and almost nobody outside its own small circle of volunteers ever thinks about who maintains it. Those volunteers have now held their annual Contributors’ Summit, and Johannes Schindelin, a longtime Git developer, has posted a detailed account of what they discussed to the project’s mailing list, as covered by LWN.net.

The largest item is Git 3.0. The next major version of the tool has been in the works for years, at the centre of it a change of hash function: the move away from SHA-1, the aging algorithm that identifies every commit and is no longer trusted to resist attack, toward SHA-256. A switch like that touches every repository and every hosting service, which is why it has crept rather than marched. Discussion of the v3.0 timeline at the summit was aimed at settling when the turn actually comes.

## Security and machines

The project’s security process came in for its own debate. For a piece of software that sits beneath banks, governments and the companies that host the world’s code, how a flaw is reported, fixed and disclosed is not a clerical matter, and the maintainers spent summit time on how theirs should work.

Two other threads run through the posted summary. One is the pluggable object database, work that would let Git swap out the machinery it uses to store its data, a slow rebuild of the tool’s foundations. The other is documentation, the unfashionable chore of explaining the tool to the millions who use it and the smaller number who might one day maintain it.

The summit also took up a question now facing every software project: what to do about large language models. AI tools that write code have reached the Git project, as they have reached everywhere else, and the maintainers have to decide what place, if any, machine-written work has in a codebase this widely depended upon.

None of it comes with fanfare. There is no launch event for Git; there is a mailing list and a posted summary. The debates at one small gathering of volunteers, over version numbers, hash functions and disclosure rules, will determine how the world’s software keeps its own records for the next decade.
