It seems OpenPGP is still riddled with SHA-1. Git kind of avoided the problem (https://github.blog/2017-03-20-sha-1-collision-detection-on-...). What's your plan to deal with the issue?
This is the same algorithm used by git.
There are higher level implementations that use the dates on signatures to straight out reject sha1 material, but that gives only a limited protection.