We are pleased to announce the availability of GnuPG version 2.2.18.
This is maintenance release to fix a couple of minor bugs and provide
a few feature updates. This release also retires the use of SHA-1 key
signatures created since this year. {[[https://lists.gnupg.org/pipermail/gnupg-announce/2019q4/000442.html][more]]} ([[https://lists.gnupg.org/pipermail/gnupg-announce/2019q4/000443.html][see also]])
** Libgcrypt 1.8.5 released (2019-08-29)
If you care about local site-channel attacks on ECDSA you may want to
update to [[file:software/libgcrypt/index.org][Libgcrypt]] version 1.8.5. {{{CVE(CVE-2019-13627)}}} {[[https://lists.gnupg.org/pipermail/gnupg-announce/2019q3/000440.html][more]]}
* COMMENT
This is the publishing info used for the GnuPG pages