https://bz.apache.org/SpamAssassin/show_bug.cgi?id=7618

Sidney Markowitz <sid...@sidney.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |RESOLVED
         Resolution|---                         |FIXED

--- Comment #27 from Sidney Markowitz <sid...@sidney.com> ---
This issue doesn't have to be left open. On 2018-09-19 the PMC was notified by
the Board that we don't have to request a variance. The policy was changed and
now says that SHA-1 SHOULD NOT be used instead of MUST NOT. See
https://infra.apache.org/release-distribution#sigs-and-sums

We can decide when is a suitable time to stop generating SHA-1 hashes in
mkupdate, based on when we consider it suitable to add that level of extra step
to people who insist on using a sufficiently old version.

-- 
You are receiving this mail because:
You are the assignee for the bug.

Reply via email to