Then use a SHA256-based repo, and use the cheaper signing scheme.
For some people, an improved signing scheme over the SHA-1-linked repository format would meet their requirements based on their assessment of their security threats.
For some people, an improved signing scheme over the SHA-1-linked repository format would meet their requirements based on their assessment of their security threats.
The scheme you just called a "screw up"?