DFSG NEW Queue

DFSG, Licensing & New Packages Team

Review: golang-filippo-nistec 0.0.4-2

New Package Report

.changes
Distributionunstable
DateWed, 11 Feb 2026 12:05:42 +0100
Sourcegolang-filippo-nistec
Version0.0.4-2
Changed-BySimon Josefsson
Architecturesource all
.dsc
Priorityoptional
Componentmain
Package-Listgolang-filippo-nistec-dev deb golang optional arch=all
Sectiongolang
debian/copyright
Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Source: https://github.com/FiloSottile/nistec
Upstream-Name: nistec
Upstream-Contact: Filippo Valsorda <github@filippo.io>

Files: *
Copyright: 2009-2024 The Go Authors
License: BSD-3-clause

Files: internal/fiat/*
Copyright: 2015-2020 The fiat-crypto Authors. All rights reserved.
License: BSD-1-Clause
Comment: internal/fiat/README

Files: debian/*
Copyright: 2025-2026 Simon Josefsson <simon@josefsson.org>
License: BSD-3-clause
Comment: Debian packaging is licensed under the same terms as upstream

License: BSD-1-Clause
    Redistribution and use in source and binary forms, with or without
    modification, are permitted provided that the following conditions are
    met:
 .
        1. Redistributions of source code must retain the above copyright
        notice, this list of conditions and the following disclaimer.
 .
    THIS SOFTWARE IS PROVIDED BY the fiat-crypto authors "AS IS"
    AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
    THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
    PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL Berkeley Software Design,
    Inc. BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
    EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
    PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
    PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
    LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
    NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
    SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.

License: BSD-3-clause
 Redistribution and use in source and binary forms, with or without
 modification, are permitted provided that the following conditions are
 met:
 .
   * Redistributions of source code must retain the above copyright
 notice, this list of conditions and the following disclaimer.
   * Redistributions in binary form must reproduce the above
 copyright notice, this list of conditions and the following disclaimer
 in the documentation and/or other materials provided with the
 distribution.
   * Neither the name of Google LLC nor the names of its
 contributors may be used to endorse or promote products derived from
 this software without specific prior written permission.
 .
 THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
 "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
 LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
 A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
 OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
 SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
 LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
 DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
 THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
 (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
 OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.

Review Information

rejected — allocated to siretart 1 month, 1 day ago, started 1 month, 1 day ago, completed 1 month, 1 day ago.

Final Comment

Inaccurate debian/copyright for internal/fiat: The debian/copyright file lists internal/fiat/* as being under the BSD-1-Clause license with "The fiat-crypto Authors" as copyright holders. However, several files in this directory (e.g., internal/fiat/p256.go, internal/fiat/p224.go, internal/fiat/generate.go, and the *_invert.go files) contain headers explicitly stating:

// Copyright 2021 The Go Authors. All rights reserved.
// Use of this source code is governed by a BSD-style
// license that can be found in the LICENSE file.

These copyright statements must be preserved.

Only the *_fiat64.go files and the README appear to be under the fiat-crypto BSD-1-Clause license.

Please update debian/copyright to include all copyright statements

Other Reviews of this Package

VersionHashAllocatedCompletedReviewerStatusDetails
0.0.4-3 e8784067… 2026-02-18 00:21 2026-02-18 12:10 siretart accepted VIEW
0.0.4-1 2026-02-10 23:43 2026-02-10 23:49 siretart rejected VIEW

Back to Dashboard | View all reviews for this package