DFSG NEW Queue

DFSG, Licensing & New Packages Team

Review: rust-ghac 0.3.0-1

Package Information

DescriptionGenerated protobuf definitions for GitHub Actions Cache service V2 - Rust source code

Generated Rust protobuf/gRPC definitions for the GitHub Actions Cache service V2, as used by the ghac service of the opendal crate.Source code for Debianized Rust crate "ghac"

MaintainerDebian Rust Maintainers <pkg-rust-maintainers@alioth-lists.debian.net>
Changed BySylvestre Ledru <sylvestre@debian.org>
Sponsorsylvestre@debian.org
Distributionunstable
Architectureany
VCSgit: https://salsa.debian.org/rust-team/debcargo-conf.git [src/ghac] (browse)
Trackerhttps://tracker.debian.org/pkg/rust-ghac
Uploaded1 month, 11 days ago

New Package Report

.changes
Version0.3.0-1
Changed-BySylvestre Ledru
Architectureamd64 source
Distributionunstable
DateWed, 12 Aug 2026 09:25:31 +0000
Sourcerust-ghac
Changelog
rust-ghac (0.3.0-1) unstable; urgency=medium
 .
   * Package ghac 0.3.0 from crates.io using debcargo 2.8.4
.dsc
Sectionrust
Priorityoptional
Componentmain
Package-Listlibrust-ghac-dev deb rust optional arch=any
debian/copyright
Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Upstream-Name: ghac
Upstream-Contact: Xuanwo <github@xuanwo.io>
Source: https://github.com/Xuanwo/ghac

Files: *
Copyright:
 2021 Datafuse Labs
 2025 Xuanwo <github@xuanwo.io>
License: Apache-2.0

Files: debian/*
Copyright:
 2026 Debian Rust Maintainers <pkg-rust-maintainers@alioth-lists.debian.net>
 2026 Sylvestre Ledru <sylvestre@debian.org>
License: Apache-2.0

License: Apache-2.0
 Debian systems provide the Apache 2.0 license in
 /usr/share/common-licenses/Apache-2.0

Review Information

accepted — allocated to eamanu 1 month, 10 days ago, started 1 month, 10 days ago, completed 1 month, 10 days ago.

Final Comment

Public Notes

1 month, 10 days ago ● public

Author check: rust-ghac 0.3.0-1

Scanned 16 files. 4 author(s) declared in debian/copyright.

All source-file authors appear in debian/copyright.

1 month, 10 days ago ● public

License check: rust-ghac 0.3.0-1

Archive component: main

COMPATIBLE:

  • Apache-2.0 (Note: not compatible with GPL-2)
1 month, 10 days ago ● public

licensecheck

Command: licensecheck -r --deb-machine .
Exit code: 0

Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Upstream-Name: FIXME
Upstream-Contact: FIXME
Source: FIXME
Disclaimer: Autogenerated by licensecheck

Files: ./.cargo_vcs_info.json
 ./.github/FUNDING.yml
 ./.github/dependabot.yml
 ./.github/workflows/ci.yml
 ./CODE_OF_CONDUCT.md
 ./CONTRIBUTING.md
 ./Cargo.lock
 ./Cargo.toml
 ./Cargo.toml.orig
 ./README.md
 ./debian/cargo-checksum.json
 ./debian/changelog
 ./debian/control
 ./debian/debcargo.toml
 ./debian/rules
 ./debian/source/format
 ./debian/tests/control
 ./debian/upstream/metadata
 ./debian/watch
 ./proto/cache.proto
 ./rust-toolchain.toml
 ./rustfmt.toml
 ./src/lib.rs
 ./src/v1.rs
Copyright: NONE
License: UNKNOWN
 FIXME

Files: ./LICENSE
Copyright: NONE
License: Apache-2.0
 FIXME

Files: ./debian/copyright
Copyright: 2021, Datafuse Labs
  2026, Debian Rust Maintainers <pkg-rust-maintainers@alioth-lists.debian.net>
License: Apache-2.0
 FIXME

Files: ./debian/copyright.debcargo.hint
Copyright: FIXME (overlay) UNKNOWN-AUTHORS FIXME (overlay) UNKNOWN-YEARS
License: Apache-2.0
 FIXME

1 month, 10 days ago ● public

debian/copyright check

Command: cme check dpkg-copyright
Exit code: 0

(no output)

1 month, 10 days ago ● public

licenserecon

Command: licenserecon
Exit code: 0

en: Versions: licenserecon '17.0'  licensecheck '3.3.9-1'

Parsing Source Tree  ....
Reading d/copyright  ....
Running licensecheck ....

No significant differences found
1 month, 10 days ago ● public

Look for SPDX

Command: grep -r -B1 'SPDX-'
Exit code: 1

(no output)

1 month, 10 days ago ● public

Lintian

Command: lintian -i -I -v --pedantic
Exit code: 0

N:
W: librust-ghac-dev: initial-upload-closes-no-bugs [usr/share/doc/librust-ghac-dev/changelog.Debian.gz:1]
N: 
N:   This package appears to be the first packaging of a new upstream software
N:   package (there is only one changelog entry and the Debian revision is 1),
N:   but it does not close any bugs. The initial upload of a new package should
N:   close the corresponding ITP bug for that package.
N:   
N:   This warning can be ignored if the package is not intended for Debian or
N:   if it is a split of an existing Debian package.
N: 
N:   Please refer to New packages (Section 5.1) in the Debian Developer's
N:   Reference for details.
N: 
N:   Visibility: warning
N:   Show-Always: no
N:   Check: debian/changelog
N:   Renamed from: new-package-should-close-itp-bug
N: 
N:
W: librust-ghac-dev: synopsis-too-long
N: 
N:   The first line of the "Description:" must be less than 80 characters long.
N: 
N:   Please refer to The single line synopsis (Section 3.4.1) in the Debian
N:   Policy Manual for details.
N: 
N:   Visibility: warning
N:   Show-Always: no
N:   Check: fields/description
N:   Renamed from: description-too-long
N: 
N:
I: librust-ghac-dev: package-contains-documentation-outside-usr-share-doc [usr/share/cargo/registry/ghac-0.3.0/CODE_OF_CONDUCT.md]
N: 
N:   This package ships a documentation file outside /usr/share/doc
N:   Documentation files are normally installed inside /usr/share/doc.
N:   
N:   If this file doesn't describe the contents or purpose of the directory it
N:   is in, please consider moving this file to /usr/share/doc/ or maybe even
N:   removing it. If this file does describe the contents or purpose of the
N:   directory it is in, please add a lintian override.
N: 
N:   Visibility: info
N:   Show-Always: no
N:   Check: documentation
N: 
N:   Screen: python/egg/metadata
N:     Advocates: "Scott Kitterman" <debian@kitterman.com>
N:     Reason: The folders XXX.dist-info/ and XXX.egg-info/ hold metadata for
N:             Python modules. Those files are not documentation even though
N:             some of their names carry the .txt file extension.
N:             
N:             Python modules can be both public and private.
N:             
N:             Read more in
N:             https://www.python.org/dev/peps/pep-0427/#the-dist-info-directory,
N:             https://www.python.org/dev/peps/pep-0376/#id16,
N:             https://www.python.org/dev/peps/pep-0610/,
N:             https://www.python.org/dev/peps/pep-0639/,
N:             https://setuptools.pypa.io/en/latest/deprecated/python_eggs.html,
N:             and Bug#1003913.
N: 
N:
I: librust-ghac-dev: package-contains-documentation-outside-usr-share-doc [usr/share/cargo/registry/ghac-0.3.0/CONTRIBUTING.md]
N:
I: librust-ghac-dev: package-contains-documentation-outside-usr-share-doc [usr/share/cargo/registry/ghac-0.3.0/LICENSE]
N:
I: librust-ghac-dev: package-contains-documentation-outside-usr-share-doc [usr/share/cargo/registry/ghac-0.3.0/README.md]
N:
I: rust-ghac source: upstream-metadata-missing-bug-tracking [debian/upstream/metadata]
N: 
N:   The DEP 12 metadata file does not specify any upstream bug tracking
N:   information (ie. the Bug-Database or Bug-Submit fields are missing).
N:   
N:   The upstream metadata can be found in the source package in the file
N:   debian/upstream/metadata.
N: 
N:   Please refer to https://dep-team.pages.debian.net/deps/dep12/ for details.
N: 
N:   Visibility: info
N:   Show-Always: no
N:   Check: debian/upstream/metadata
N: 
N:
P: rust-ghac source: package-uses-old-debhelper-compat-version 13
N: 
N:   This package uses a debhelper compatibility level that is no longer
N:   recommended. Please consider using the recommended level.
N:   
N:   For most packages, the best way to set the compatibility level is to
N:   specify debhelper-compat (= X) as a Build-Depends in debian/control. You
N:   can also use the debian/compat file or export DH_COMPAT in debian/rules.
N:   
N:   If no level is selected debhelper defaults to level 1, which is
N:   deprecated.
N: 
N:   Please refer to the debhelper(7) manual page for details.
N: 
N:   Visibility: pedantic
N:   Show-Always: no
N:   Check: debhelper
N: 
1 month, 10 days ago ● public

duck

Command: duck
Exit code: 0

(no output)

1 month, 10 days ago ● public

look for copyright

Command: egrep -R -i copyright
Exit code: 0

LICENSE:      "Licensor" shall mean the copyright owner or entity authorized by
LICENSE:      the copyright owner that is granting the License.
LICENSE:      copyright notice that is included in or attached to the work
LICENSE:      submitted to Licensor for inclusion in the Work by the copyright owner
LICENSE:      the copyright owner. For the purposes of this definition, "submitted"
LICENSE:      designated in writing by the copyright owner as "Not a Contribution."
LICENSE:   2. Grant of Copyright License. Subject to the terms and conditions of
LICENSE:      copyright license to reproduce, prepare Derivative Works of,
LICENSE:          that You distribute, all copyright, patent, trademark, and
LICENSE:      You may add Your own copyright statement to Your modifications and
LICENSE:      same "printed page" as the copyright notice for easier
LICENSE:   Copyright 2021 Datafuse Labs
debian/copyright.debcargo.hint:Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
debian/copyright.debcargo.hint:Copyright: FIXME (overlay) UNKNOWN-AUTHORS FIXME (overlay) UNKNOWN-YEARS
debian/copyright.debcargo.hint: FIXME (overlay): Since upstream copyright years are not available in
debian/copyright.debcargo.hint:Copyright: 2021 Datafuse Labs
debian/copyright.debcargo.hint:Copyright:
debian/copyright:Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
debian/copyright:Copyright:
debian/copyright:Copyright:
1 month, 10 days ago ● public

look for license

Command: egrep -R -i license
Exit code: 0

Cargo.toml.orig:license = "Apache-2.0"
Cargo.toml:license = "Apache-2.0"
LICENSE:                                 Apache License
LICENSE:                        http://www.apache.org/licenses/
LICENSE:      "License" shall mean the terms and conditions for use, reproduction,
LICENSE:      the copyright owner that is granting the License.
LICENSE:      exercising permissions granted by this License.
LICENSE:      Object form, made available under the License, as indicated by a
LICENSE:      of this License, Derivative Works shall not include works that remain
LICENSE:   2. Grant of Copyright License. Subject to the terms and conditions of
LICENSE:      this License, each Contributor hereby grants to You a perpetual,
LICENSE:      copyright license to reproduce, prepare Derivative Works of,
LICENSE:      publicly display, publicly perform, sublicense, and distribute the
LICENSE:   3. Grant of Patent License. Subject to the terms and conditions of
LICENSE:      this License, each Contributor hereby grants to You a perpetual,
LICENSE:      (except as stated in this section) patent license to make, have made,
LICENSE:      where such license applies only to those patent claims licensable
LICENSE:      or contributory patent infringement, then any patent licenses
LICENSE:      granted to You under this License for that Work shall terminate
LICENSE:          Derivative Works a copy of this License; and
LICENSE:          do not modify the License. You may add Your own attribution
LICENSE:          as modifying the License.
LICENSE:      may provide additional or different license terms and conditions
LICENSE:      the conditions stated in this License.
LICENSE:      this License, without any additional terms or conditions.
LICENSE:      the terms of any separate license agreement you may have executed
LICENSE:   6. Trademarks. This License does not grant permission to use the trade
LICENSE:      risks associated with Your exercise of permissions under this License.
LICENSE:      result of this License or out of the use or inability to use the
LICENSE:      License. However, in accepting such obligations, You may act only
LICENSE:   APPENDIX: How to apply the Apache License to your work.
LICENSE:      To apply the Apache License to your work, attach the following
LICENSE:   Licensed under the Apache License, Version 2.0 (the "License");
LICENSE:   you may not use this file except in compliance with the License.
LICENSE:   You may obtain a copy of the License at
LICENSE:       http://www.apache.org/licenses/LICENSE-2.0
LICENSE:   distributed under the License is distributed on an "AS IS" BASIS,
LICENSE:   See the License for the specific language governing permissions and
LICENSE:   limitations under the License.
debian/copyright.debcargo.hint:License: Apache-2.0
debian/copyright.debcargo.hint:Files: LICENSE
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: Apache-2.0
debian/copyright.debcargo.hint:License: Apache-2.0
debian/copyright.debcargo.hint: Debian systems provide the Apache 2.0 license in
debian/copyright.debcargo.hint: /usr/share/common-licenses/Apache-2.0
debian/copyright:License: Apache-2.0
debian/copyright:License: Apache-2.0
debian/copyright:License: Apache-2.0
debian/copyright: Debian systems provide the Apache 2.0 license in
debian/copyright: /usr/share/common-licenses/Apache-2.0
README.md:#### License
README.md:Licensed under <a href="./LICENSE">Apache License, Version 2.0</a>.

Back to Dashboard | View all reviews for this package