DFSG NEW Queue

DFSG, Licensing & New Packages Team

Review: rust-mp4parse 0.17.0-2

Package Information

DescriptionParser for ISO base media file format (mp4) - Rust source code

Source code for Debianized Rust crate "mp4parse"

MaintainerDebian Rust Maintainers <pkg-rust-maintainers@alioth-lists.debian.net>
Changed ByJeremy Bícha <jbicha@ubuntu.com>
Sponsorjbicha@debian.org
Distributionunstable
Architectureany
VCSgit: https://salsa.debian.org/rust-team/debcargo-conf.git [src/mp4parse] (browse)
Trackerhttps://tracker.debian.org/pkg/rust-mp4parse
Uploaded8 days ago

New Package Report

.changes
Sourcerust-mp4parse
Version0.17.0-2
Changed-ByJeremy Bícha
Architecturesource amd64
Distributionunstable
.dsc
Package-Listlibrust-mp4parse-dev deb rust optional arch=any
Sectionrust
Priorityoptional
Componentmain
debian/copyright
Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Upstream-Name: mp4parse
Upstream-Contact:
 Ralph Giles <giles@mozilla.com>
 Matthew Gregan <kinetik@flim.org>
 Alfredo Yang <ayang@mozilla.com>
 Jon Bauman <jbauman@mozilla.com>
 Bryce Seager van Dyk <bvandyk@mozilla.com>
Source: https://github.com/mozilla/mp4parse-rust

Files: *
Copyright:
 2016-2018 Ralph Giles <giles@mozilla.com>
 2016-2025 Matthew Gregan <kinetik@flim.org>
 2020-2022 Jon Bauman <jbauman@mozilla.com>
 2018-2020 Bryce Seager van Dyk <bvandyk@mozilla.com>
 Alfredo Yang <ayang@mozilla.com>
License: MPL-2.0

Files: debian/*
Copyright:
 2025-2026 Debian Rust Maintainers <pkg-rust-maintainers@alioth-lists.debian.net>
 2025-2026 Jeremy Bícha <jbicha@ubuntu.com>
License: MPL-2.0

License: MPL-2.0
 Debian systems provide the MPL 2.0 in /usr/share/common-licenses/MPL-2.0

Review Information

rejected — allocated to siretart 11 days ago, started 11 days ago, completed 9 days ago.

Final Comment

In the archive ./tests/corrupt/invalid-avif-colr-multiple.zip I found two files that appear to be Copyright Apple Inc., 2015.
I couldn't find where they are coming from and am concerned that they may have been copied in an unauthrized manner. Please clarify the licensing situation with upstream and document the findings in Debian/copyright. In the mean time, I'd recommend removing those test files before uploading to Debian.

Back to Dashboard | View all reviews for this package