DFSG NEW Queue

DFSG, Licensing & New Packages Team

Review: rust-ossl 1.5.2-1

Package Information

DescriptionOpenSSL version 3+ bindings to modern EVP APIs - Rust source code

Source code for Debianized Rust crate "ossl"

MaintainerDebian Rust Maintainers <pkg-rust-maintainers@alioth-lists.debian.net>
Changed ByAlexander Kjäll <alexander.kjall@gmail.com>
Distributionunstable
Architectureany
VCSgit: https://salsa.debian.org/rust-team/debcargo-conf.git [src/ossl] (browse)
Trackerhttps://tracker.debian.org/pkg/rust-ossl
Uploaded28 days ago

New Package Report

.changes
Changed-ByAlexander Kjäll
Architectureamd64 source
Distributionunstable
DateMon, 24 Aug 2026 19:06:48 +0000
Sourcerust-ossl
Version1.5.2-1
Changelog
rust-ossl (1.5.2-1) unstable; urgency=medium
 .
   * Package ossl 1.5.2 from crates.io using debcargo 2.8.4
.dsc
Sectionrust
Priorityoptional
Componentmain
Package-Listlibrust-ossl-dev deb rust optional arch=any
debian/copyright
Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Upstream-Name: ossl
Upstream-Contact: Simo Sorce and Jakub Jelen
Source: https://github.com/latchset/kryoptic

Files: *
Copyright:
 2025-2026 Simo Sorce
 2025-2026 Jakub Jelen
License: Apache-2.0

Files: debian/*
Copyright:
 2026 Debian Rust Maintainers <pkg-rust-maintainers@alioth-lists.debian.net>
 2026 Alexander Kjäll <alexander.kjall@gmail.com>
License: Apache-2.0

License: Apache-2.0
 Debian systems provide the Apache 2.0 license in
 /usr/share/common-licenses/Apache-2.0

Review Information

accepted — allocated to eamanu 28 days ago, started 28 days ago, completed 28 days ago.

Final Comment

Public Notes

28 days ago ● public

Author check: rust-ossl 1.5.2-1

Scanned 24 files. 4 author(s) declared in debian/copyright.

All source-file authors appear in debian/copyright.

28 days ago ● public

License check: rust-ossl 1.5.2-1

Archive component: main

COMPATIBLE:

  • Apache-2.0 (Note: not compatible with GPL-2)
28 days ago ● public

licensecheck

Command: licensecheck -r --deb-machine .
Exit code: 0

Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Upstream-Name: FIXME
Upstream-Contact: FIXME
Source: FIXME
Disclaimer: Autogenerated by licensecheck

Files: ./.cargo_vcs_info.json
 ./Cargo.lock
 ./Cargo.toml
 ./Cargo.toml.orig
 ./README.md
 ./debian/cargo-checksum.json
 ./debian/changelog
 ./debian/control
 ./debian/debcargo.toml
 ./debian/patches/disable-ossl-sys.patch
 ./debian/patches/series
 ./debian/rules
 ./debian/source/format
 ./debian/tests/control
 ./debian/upstream/metadata
 ./debian/watch
 ./src/non-openssl-sys-bindings.rs
Copyright: NONE
License: UNKNOWN
 FIXME

Files: ./build.rs
 ./src/asymcipher.rs
 ./src/cipher.rs
 ./src/derive.rs
 ./src/digest.rs
 ./src/fips.rs
 ./src/lib.rs
 ./src/mac.rs
 ./src/pkey.rs
 ./src/rand.rs
 ./src/signature.rs
 ./src/tests/aes.rs
 ./src/tests/brainpool.rs
 ./src/tests/mod.rs
Copyright: 2025, Simo Sorce
  2026, Simo Sorce
License: UNKNOWN
 FIXME

Files: ./src/tests/cipher.rs
 ./src/tests/digest.rs
 ./src/tests/dsa.rs
Copyright: 2025, Jakub Jelen
License: UNKNOWN
 FIXME

Files: ./LICENSE-2.0.txt
Copyright: NONE
License: Apache-2.0
 FIXME

Files: ./debian/copyright
Copyright: 2025-2026, Simo Sorce
  2026, Debian Rust Maintainers <pkg-rust-maintainers@alioth-lists.debian.net>
License: Apache-2.0
 FIXME

Files: ./debian/copyright.debcargo.hint
Copyright: FIXME (overlay) UNKNOWN-AUTHORS FIXME (overlay) UNKNOWN-YEARS
License: Apache-2.0
 FIXME

28 days ago ● public

debian/copyright check

Command: cme check dpkg-copyright
Exit code: 0

(no output)

28 days ago ● public

licenserecon

Command: licenserecon
Exit code: 0

en: Versions: licenserecon '17.0'  licensecheck '3.3.9-1'

Parsing Source Tree  ....
Reading d/copyright  ....
Running licensecheck ....

No significant differences found
28 days ago ● public

Look for SPDX

Command: grep -r -B1 'SPDX-'
Exit code: 1

(no output)

28 days ago ● public

Lintian

Command: lintian -i -I -v --pedantic
Exit code: 0

N:
W: librust-ossl-dev: initial-upload-closes-no-bugs [usr/share/doc/librust-ossl-dev/changelog.Debian.gz:1]
N: 
N:   This package appears to be the first packaging of a new upstream software
N:   package (there is only one changelog entry and the Debian revision is 1),
N:   but it does not close any bugs. The initial upload of a new package should
N:   close the corresponding ITP bug for that package.
N:   
N:   This warning can be ignored if the package is not intended for Debian or
N:   if it is a split of an existing Debian package.
N: 
N:   Please refer to New packages (Section 5.1) in the Debian Developer's
N:   Reference for details.
N: 
N:   Visibility: warning
N:   Show-Always: no
N:   Check: debian/changelog
N:   Renamed from: new-package-should-close-itp-bug
N: 
N:
I: librust-ossl-dev: extended-description-is-probably-too-short
N: 
N:   The extended description (the lines after the first line of the
N:   "Description:" field) is only one or two lines long. The extended
N:   description should provide a user with enough information to decide
N:   whether they want to install this package, what it contains, and how it
N:   compares to similar packages. One or two lines is normally not enough to
N:   do this.
N: 
N:   Please refer to General guidelines for package descriptions (Section
N:   6.2.1) in the Debian Developer's Reference and The long description
N:   (Section 6.2.3) in the Debian Developer's Reference for details.
N: 
N:   Visibility: info
N:   Show-Always: no
N:   Check: fields/description
N: 
N:
I: librust-ossl-dev: package-contains-documentation-outside-usr-share-doc [usr/share/cargo/registry/ossl-1.5.2/LICENSE-2.0.txt]
N: 
N:   This package ships a documentation file outside /usr/share/doc
N:   Documentation files are normally installed inside /usr/share/doc.
N:   
N:   If this file doesn't describe the contents or purpose of the directory it
N:   is in, please consider moving this file to /usr/share/doc/ or maybe even
N:   removing it. If this file does describe the contents or purpose of the
N:   directory it is in, please add a lintian override.
N: 
N:   Visibility: info
N:   Show-Always: no
N:   Check: documentation
N: 
N:   Screen: python/egg/metadata
N:     Advocates: "Scott Kitterman" <debian@kitterman.com>
N:     Reason: The folders XXX.dist-info/ and XXX.egg-info/ hold metadata for
N:             Python modules. Those files are not documentation even though
N:             some of their names carry the .txt file extension.
N:             
N:             Python modules can be both public and private.
N:             
N:             Read more in
N:             https://www.python.org/dev/peps/pep-0427/#the-dist-info-directory,
N:             https://www.python.org/dev/peps/pep-0376/#id16,
N:             https://www.python.org/dev/peps/pep-0610/,
N:             https://www.python.org/dev/peps/pep-0639/,
N:             https://setuptools.pypa.io/en/latest/deprecated/python_eggs.html,
N:             and Bug#1003913.
N: 
N:
I: librust-ossl-dev: package-contains-documentation-outside-usr-share-doc [usr/share/cargo/registry/ossl-1.5.2/README.md]
N:
I: rust-ossl source: quilt-patch-missing-description [debian/patches/disable-ossl-sys.patch]
N: 
N:   quilt patch files should start with a description of patch. All lines
N:   before the start of the patch itself are considered part of the
N:   description. You can edit the description with quilt header -e when the
N:   patch is at the top of the stack.
N:   
N:   As well as a description of the purpose and function of the patch, the
N:   description should ideally contain author information, a URL for the bug
N:   report (if any), Debian or upstream bugs fixed by it, upstream status, the
N:   Debian version and date the patch was first included, and any other
N:   information that would be useful if someone were investigating the patch
N:   and underlying problem. Please consider using the DEP 3 format for this
N:   information.
N: 
N:   Please refer to https://dep-team.pages.debian.net/deps/dep3/ for details.
N: 
N:   Visibility: info
N:   Show-Always: no
N:   Check: debian/patches/quilt
N: 
N:
I: rust-ossl source: upstream-metadata-missing-bug-tracking [debian/upstream/metadata]
N: 
N:   The DEP 12 metadata file does not specify any upstream bug tracking
N:   information (ie. the Bug-Database or Bug-Submit fields are missing).
N:   
N:   The upstream metadata can be found in the source package in the file
N:   debian/upstream/metadata.
N: 
N:   Please refer to https://dep-team.pages.debian.net/deps/dep12/ for details.
N: 
N:   Visibility: info
N:   Show-Always: no
N:   Check: debian/upstream/metadata
N: 
N:
P: rust-ossl source: package-uses-old-debhelper-compat-version 13
N: 
N:   This package uses a debhelper compatibility level that is no longer
N:   recommended. Please consider using the recommended level.
N:   
N:   For most packages, the best way to set the compatibility level is to
N:   specify debhelper-compat (= X) as a Build-Depends in debian/control. You
N:   can also use the debian/compat file or export DH_COMPAT in debian/rules.
N:   
N:   If no level is selected debhelper defaults to level 1, which is
N:   deprecated.
N: 
N:   Please refer to the debhelper(7) manual page for details.
N: 
N:   Visibility: pedantic
N:   Show-Always: no
N:   Check: debhelper
N: 
28 days ago ● public

duck

Command: duck
Exit code: 0

I: debian/upstream/metadata:URL: https://github.com/latchset/kryoptic: INFORMATION (Certainty:wild-guess)
   Curl:0 HTTP:200 No error 
   Website seems to be outdated, is probably a parked domain or for sale. Please update your links!
   Matching regular expression(s):
    m/\bhas been moved\b/i
    m/\bmoved to\b/i

I: debian/copyright:4: URL: https://github.com/latchset/kryoptic: INFORMATION (Certainty:wild-guess)
   Curl:0 HTTP:200 No error 
   Website seems to be outdated, is probably a parked domain or for sale. Please update your links!
   Matching regular expression(s):
    m/\bhas been moved\b/i
    m/\bmoved to\b/i

I: debian/upstream/metadata:URL: https://github.com/latchset/kryoptic.git: INFORMATION (Certainty:wild-guess)
   Curl:0 HTTP:200 No error 
   Website seems to be outdated, is probably a parked domain or for sale. Please update your links!
   Matching regular expression(s):
    m/\bhas been moved\b/i
    m/\bmoved to\b/i

I: debian/control: Homepage: https://github.com/latchset/kryoptic: INFORMATION (Certainty:wild-guess)
   Curl:0 HTTP:200 No error 
   Website seems to be outdated, is probably a parked domain or for sale. Please update your links!
   Matching regular expression(s):
    m/\bhas been moved\b/i
    m/\bmoved to\b/i

28 days ago ● public

look for copyright

Command: egrep -R -i copyright
Exit code: 0

LICENSE-2.0.txt:      "Licensor" shall mean the copyright owner or entity authorized by
LICENSE-2.0.txt:      the copyright owner that is granting the License.
LICENSE-2.0.txt:      copyright notice that is included in or attached to the work
LICENSE-2.0.txt:      submitted to Licensor for inclusion in the Work by the copyright owner
LICENSE-2.0.txt:      the copyright owner. For the purposes of this definition, "submitted"
LICENSE-2.0.txt:      designated in writing by the copyright owner as "Not a Contribution."
LICENSE-2.0.txt:   2. Grant of Copyright License. Subject to the terms and conditions of
LICENSE-2.0.txt:      copyright license to reproduce, prepare Derivative Works of,
LICENSE-2.0.txt:          that You distribute, all copyright, patent, trademark, and
LICENSE-2.0.txt:      You may add Your own copyright statement to Your modifications and
debian/copyright.debcargo.hint:Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
debian/copyright.debcargo.hint:Copyright: FIXME (overlay) UNKNOWN-AUTHORS FIXME (overlay) UNKNOWN-YEARS
debian/copyright.debcargo.hint: FIXME (overlay): Since upstream copyright years are not available in
debian/copyright.debcargo.hint:Copyright: 2025 Simo Sorce
debian/copyright.debcargo.hint:Copyright: 2025 Simo Sorce
debian/copyright.debcargo.hint:Copyright: 2025 Simo Sorce
debian/copyright.debcargo.hint:Copyright: 2025 Simo Sorce
debian/copyright.debcargo.hint:Copyright: 2025 Simo Sorce
debian/copyright.debcargo.hint:Copyright: 2025 Simo Sorce
debian/copyright.debcargo.hint:Copyright: 2025 Simo Sorce
debian/copyright.debcargo.hint:Copyright: 2025 Simo Sorce
debian/copyright.debcargo.hint:Copyright: 2025 Simo Sorce
debian/copyright.debcargo.hint:Copyright: 2025 Simo Sorce
debian/copyright.debcargo.hint:Copyright: 2025 Simo Sorce
debian/copyright.debcargo.hint:Copyright: 2026 Simo Sorce
debian/copyright.debcargo.hint:Copyright: 2025 Simo Sorce
debian/copyright.debcargo.hint:Copyright: 2025 Jakub Jelen
debian/copyright.debcargo.hint:Copyright: 2025 Jakub Jelen
debian/copyright.debcargo.hint:Copyright: 2025 Jakub Jelen
debian/copyright.debcargo.hint:Copyright: 2025 Simo Sorce
debian/copyright.debcargo.hint:Copyright:
debian/copyright:Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
debian/copyright:Copyright:
debian/copyright:Copyright:
src/pkey.rs:// Copyright 2025 Simo Sorce
src/tests/aes.rs:// Copyright 2026 Simo Sorce
src/tests/digest.rs:// Copyright 2025 Jakub Jelen
src/tests/cipher.rs:// Copyright 2025 Jakub Jelen
src/tests/mod.rs:// Copyright 2025 Simo Sorce
src/tests/brainpool.rs:// Copyright 2025 Simo Sorce
src/tests/dsa.rs:// Copyright 2025 Jakub Jelen
src/asymcipher.rs:// Copyright 2025 Simo Sorce
src/digest.rs:// Copyright 2025 Simo Sorce
src/lib.rs:// Copyright 2025 Simo Sorce
src/mac.rs:// Copyright 2025 Simo Sorce
src/cipher.rs:// Copyright 2025 Simo Sorce
src/signature.rs:// Copyright 2025 Simo Sorce
src/rand.rs:// Copyright 2025 Simo Sorce
src/derive.rs:// Copyright 2025 Simo Sorce
src/fips.rs:// Copyright 2025 Simo Sorce
build.rs:// Copyright 2025 Simo Sorce
28 days ago ● public

look for license

Command: egrep -R -i license
Exit code: 0

.pc/disable-ossl-sys.patch/Cargo.toml:license = "Apache-2.0"
Cargo.toml.orig:license = "Apache-2.0"
Cargo.toml:license = "Apache-2.0"
LICENSE-2.0.txt:                                 Apache License
LICENSE-2.0.txt:                        https://www.apache.org/licenses/
LICENSE-2.0.txt:      "License" shall mean the terms and conditions for use, reproduction,
LICENSE-2.0.txt:      the copyright owner that is granting the License.
LICENSE-2.0.txt:      exercising permissions granted by this License.
LICENSE-2.0.txt:      Object form, made available under the License, as indicated by a
LICENSE-2.0.txt:      of this License, Derivative Works shall not include works that remain
LICENSE-2.0.txt:   2. Grant of Copyright License. Subject to the terms and conditions of
LICENSE-2.0.txt:      this License, each Contributor hereby grants to You a perpetual,
LICENSE-2.0.txt:      copyright license to reproduce, prepare Derivative Works of,
LICENSE-2.0.txt:      publicly display, publicly perform, sublicense, and distribute the
LICENSE-2.0.txt:   3. Grant of Patent License. Subject to the terms and conditions of
LICENSE-2.0.txt:      this License, each Contributor hereby grants to You a perpetual,
LICENSE-2.0.txt:      (except as stated in this section) patent license to make, have made,
LICENSE-2.0.txt:      where such license applies only to those patent claims licensable
LICENSE-2.0.txt:      or contributory patent infringement, then any patent licenses
LICENSE-2.0.txt:      granted to You under this License for that Work shall terminate
LICENSE-2.0.txt:          Derivative Works a copy of this License; and
LICENSE-2.0.txt:          do not modify the License. You may add Your own attribution
LICENSE-2.0.txt:          as modifying the License.
LICENSE-2.0.txt:      may provide additional or different license terms and conditions
LICENSE-2.0.txt:      the conditions stated in this License.
LICENSE-2.0.txt:      this License, without any additional terms or conditions.
LICENSE-2.0.txt:      the terms of any separate license agreement you may have executed
LICENSE-2.0.txt:   6. Trademarks. This License does not grant permission to use the trade
LICENSE-2.0.txt:      risks associated with Your exercise of permissions under this License.
LICENSE-2.0.txt:      result of this License or out of the use or inability to use the
LICENSE-2.0.txt:      License. However, in accepting such obligations, You may act only
debian/copyright.debcargo.hint:License: Apache-2.0
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: UNKNOWN-LICENSE; FIXME (overlay)
debian/copyright.debcargo.hint:License: Apache-2.0
debian/copyright.debcargo.hint:License: Apache-2.0
debian/copyright.debcargo.hint: Debian systems provide the Apache 2.0 license in
debian/copyright.debcargo.hint: /usr/share/common-licenses/Apache-2.0
debian/copyright:License: Apache-2.0
debian/copyright:License: Apache-2.0
debian/copyright:License: Apache-2.0
debian/copyright: Debian systems provide the Apache 2.0 license in
debian/copyright: /usr/share/common-licenses/Apache-2.0
debian/patches/disable-ossl-sys.patch:@@ -26,21 +26,12 @@ license = "Apache-2.0"
src/pkey.rs:// See LICENSE.txt file for terms
src/tests/aes.rs:// See LICENSE.txt file for terms
src/tests/digest.rs:// See LICENSE.txt file for terms
src/tests/cipher.rs:// See LICENSE.txt file for terms
src/tests/mod.rs:// See LICENSE.txt file for terms
src/tests/brainpool.rs:// See LICENSE.txt file for terms
src/tests/dsa.rs:// See LICENSE.txt file for terms
src/asymcipher.rs:// See LICENSE.txt file for terms
src/digest.rs:// See LICENSE.txt file for terms
src/lib.rs:// See LICENSE.txt file for terms
src/mac.rs:// See LICENSE.txt file for terms
src/cipher.rs:// See LICENSE.txt file for terms
src/signature.rs:// See LICENSE.txt file for terms
src/rand.rs:// See LICENSE.txt file for terms
src/derive.rs:// See LICENSE.txt file for terms
src/fips.rs:// See LICENSE.txt file for terms
build.rs:// See LICENSE.txt file for terms

Back to Dashboard | View all reviews for this package