Worth to keep in mind though that the gpg signature basically only signs the (git) hashes of the contained objects, so the choice of hash function is indeed important for security.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
replies: