Try to see what is in the sources file and use it. Only if that fails we check the configuration.
This will allow deployments that are migrating to new checksum to use it only for some packages.
The question is how to actually force the migration. Assuming a package that currently has MD5 sources, one would have to delete the sources file and upload new ones with client configured to use SHA512. That is not a very obvious process.
Try to see what is in the sources file and use it. Only if that fails we check the configuration.
This will allow deployments that are migrating to new checksum to use it only for some packages.
The question is how to actually force the migration. Assuming a package that currently has MD5 sources, one would have to delete the sources file and upload new ones with client configured to use SHA512. That is not a very obvious process.