DFSG NEW Queue

DFSG, Licensing & New Packages Team

Review: golang-github-sigstore-cosign-v2 2.6.2-1

New Package Report

.changes
Changed-BySimon Josefsson
Architecturesource all
Distributionunstable
DateThu, 02 Apr 2026 08:38:43 +0200
Sourcegolang-github-sigstore-cosign-v2
Version2.6.2-1
Changelog
golang-github-sigstore-cosign-v2 (2.6.2-1) unstable; urgency=medium
 .
   * Forked from golang-github-sigstore-cosign v2.6.2-1
     - The v2 branch is needed by the go-witness eco-system
     - Dropped binary 'cosign'
.dsc
Priorityoptional
Componentmain
Package-Listgolang-github-sigstore-cosign-v2-dev deb golang optional arch=all
Sectiongolang
debian/copyright
Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Upstream-Name: cosign
Source: https://github.com/sigstore/cosign

Files: *
Copyright: 2021-2025 The Sigstore Authors
License: Apache-2.0

Files: pkg/cosign/fulcioverifier/ctutil/ctutil.go pkg/cosign/fulcioverifier/ctutil/ctutil_test.go
Copyright: Copyright 2018 Google LLC. All Rights Reserved.
License: Apache-2.0

Files: debian/*
Copyright: 2024-2026 Simon Josefsson <simon@josefsson.org>
License: Apache-2.0
Comment: Debian packaging is licensed under the same terms as upstream

License: Apache-2.0
 Licensed under the Apache License, Version 2.0 (the "License");
 you may not use this file except in compliance with the License.
 You may obtain a copy of the License at
 .
 http://www.apache.org/licenses/LICENSE-2.0
 .
 Unless required by applicable law or agreed to in writing, software
 distributed under the License is distributed on an "AS IS" BASIS,
 WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 See the License for the specific language governing permissions and
 limitations under the License.
Comment:
 On Debian systems, the complete text of the Apache version 2.0 license
 can be found in "/usr/share/common-licenses/Apache-2.0".

Review Information

accepted — allocated to awm 11 days ago, started 11 days ago, completed 11 days ago.

Final Comment

Back to Dashboard | View all reviews for this package