GPG signatures are using SHA-1 digests #44714
Labels
C-enhancement
Category: An issue proposing an enhancement or a PR with one.
T-infra
Relevant to the infrastructure team, which will review and decide on the PR/issue.
The relevant information there is "digest algo".
1 is MD5, 2 is SHA1, 8 is SHA256, 10 is SHA512. (see RFC 4880, 9.4 for all values)
Passing e.g.
--personal-digest-preferences SHA256
to gpg would create a signature withdigest algo 8
. (or addingpersonal-digest-preferences SHA256
to the gpg config)The text was updated successfully, but these errors were encountered: