The U.S. National Institute of Standards and Technology has banned the use of SHA-1 by U.S. federal agencies since 2010.
Use SHA-256 for passphrases mangling / key stretching when using symmetric encryption .
Better solution would be Argon 2id, but GPG doesn't support it (now?).