Address review nits in sha256convert
main·
Commit

- signBranchTips: explain the os.Stderr departure from req.Out; TTY inheritance is required for gpg/ssh-agent prompts.
- Don't double-count when a commit/tag has both Signature and SignatureSHA256 (two encodings of the same signature). Relabel the warning to "signature(s) / mergetag header(s)" so the count matches what it actually represents.
- writeOriginNotes now honors SOURCE_DATE_EPOCH and otherwise pins the wrapper-commit timestamp to the Unix epoch, so the notes-ref hash is reproducible across runs over identical source state. The timestamp is bookkeeping; it carries no information about the underlying SHA1 history.
- writeLoose uses zlib level 1, matching git's core.looseCompression default — loose objects are short-lived before gc packs them, so write speed > size.
- Clarify encodeBody's "scratch MemoryObject" comment so the unused format argument is no longer mystifying on re-read.
Entire-Checkpoint: cabf3e19b5f2
Checkpoints
Checkpoint 1