What are examples of when a crypto item is publicly accessible through ASF servers?
The obvious example is including something like an OpenSSL binary within a product distribution from a /dist URL. The less obvious example , is the point at which a subversion repository starts to include code that is specially designed to work with any other 5D002 item, whether that item is ever to be included within a product distribution or not. In other words, a project should send out a notification email just after making the decision to include code that is specially designed to work with crypto APIs but before actually committing such code. No need to worry about surprise JIRA attachments with such code — only the event of committing the code to the ASF product repository.