What about hash collision?
You could write an obfuscator to keep appending useless code or comments to the payload to continually generate commit hashes until you get a collision with the same original hash.
A lot of work of course, and the hash is so f-ing huge it might take a few thousand compute-years, but you know, hackers find a way.
If nothing else, use the full 40-char hash to ensure that your attacker has to find the same atom twice across 10 moons.