Hi Simon, On Wed, 2024-03-27 at 17:14 +0100, Simon Josefsson wrote: > I wonder if the sha1cd test data is copyrighted and licensed as per > upstream's claims, but I have no fact to speak against the claim either > so I will merely make this comment about it.
Your concerns are valid, so I've done some digging and found that shattered-1.pdf and shattered- 2.pdf come from https://shattered.io, and sha-mbles-1.bin and sha-mbles-2.bin come from https://github.com/SHA-mbles/SHA-mbles.github.io I've confirmed that the sha-mbles files are licensed under Expat (and will add that to d/copyright), but I cannot find a license nor copyright for shattered, nor any contact information. Should I repack sha1cd to remove the shattered files? > I only took a look at the first package below, but the added > dependencies made it too complicated for me to build right now. Maybe > more later... You'll probably want to look at and build go-billy and go-git-fixtures first. > Thanks, Maytham
signature.asc
Description: This is a digitally signed message part