https://bz.apache.org/SpamAssassin/show_bug.cgi?id=7618
Sidney Markowitz <sid...@sidney.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution|--- |FIXED --- Comment #27 from Sidney Markowitz <sid...@sidney.com> --- This issue doesn't have to be left open. On 2018-09-19 the PMC was notified by the Board that we don't have to request a variance. The policy was changed and now says that SHA-1 SHOULD NOT be used instead of MUST NOT. See https://infra.apache.org/release-distribution#sigs-and-sums We can decide when is a suitable time to stop generating SHA-1 hashes in mkupdate, based on when we consider it suitable to add that level of extra step to people who insist on using a sufficiently old version. -- You are receiving this mail because: You are the assignee for the bug.