@soatok @eltrac @cheeaun it's reasonably easy to think of various scenarios. But I suspect that whatever I say, the reply will be "that's not a real problem" or "there are other ways to protect against that".
Suffice it to say that I'm not worried about specific scenarios that I can envision. It's the ones that may happen in the future I'm concerned about. Proving the chain of changes is what I think itbis is just a good idea. Especially since my primary project uses SHA1 hashes.