DFSG NEW Queue

DFSG, Licensing & New Packages Team

Review: xgrammar 0.2.3-1

Package Information

DescriptionEfficient, Flexible and Portable Structured Generation

XGrammar is an open-source library for efficient, flexible, and portable structured generation. It supports general context-free grammar to enable a broad range of structures while bringing careful system optimizations to enable fast executions. XGrammar features a minimal and portable C++ backend that can be easily integrated into multiple environments and frameworks, and is co-designed with the LLM inference engine and enables zero-overhead structured generation in LLM inference.

MaintainerDebian Python Team <team+python@tracker.debian.org>
Changed ByMo Zhou <lumin@debian.org>
Sponsorlumin@debian.org
Distributionunstable
Architectureamd64 arm64
VCSgit: https://salsa.debian.org/python-team/packages/xgrammar.git (browse)
Trackerhttps://tracker.debian.org/pkg/xgrammar
Uploaded2 months, 7 days ago

New Package Report

.changes
Sourcexgrammar
Version0.2.3-1
Changed-ByMo Zhou
Architecturesource amd64
Distributionunstable
DateThu, 16 Jul 2026 19:12:38 -0700
Changelog
xgrammar (0.2.3-1) unstable; urgency=medium
 .
   [ Mo Zhou ]
   * New upstream version 0.2.3
   * Add myself to uploaders (as GSoC Mentor).
 .
   [ Dylan Aïssi ]
   * Remove unneeded build-deps: python3-transformers (duplicated) and python3-all
 .
   [ Kohei Sendai <kouhei.sendai@gmail.com> ]
   * Initial release.
.dsc
Package-Listpython3-xgrammar deb python optional arch=amd64,arm64
Sectionpython
Priorityoptional
Componentmain
debian/copyright
Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Source: https://github.com/mlc-ai/xgrammar
Upstream-Name: xgrammar

Files: *
Copyright: 2024-2026 XGrammar Contributors
License: Apache-2.0

Files: 3rdparty/picojson/picojson.h
Copyright: 2009-2010 Cybozu Labs, Inc.
           2011-2014 Kazuho Oku
License: BSD-2-Clause

Files: docs/wrap_run_llm.py
Copyright: 2023 SGLang Project
License: Apache-2.0

Files: examples/benchmark/bench_apply_token_bitmask_inplace.py
       python/xgrammar/kernels/apply_token_bitmask_inplace_cuda.cu
       python/xgrammar/kernels/apply_token_bitmask_inplace_cuda.py
Copyright: 2025 NVIDIA CORPORATION & AFFILIATES
License: Apache-2.0

Files: debian/*
Copyright: 2025 Kohei Sendai <kouhei.sendai@gmail.com>
License: Apache-2.0

License: Apache-2.0
 Licensed under the Apache License, Version 2.0 (the "License");
 you may not use this file except in compliance with the License.
 You may obtain a copy of the License at
 .
 http://www.apache.org/licenses/LICENSE-2.0
 .
 Unless required by applicable law or agreed to in writing, software
 distributed under the License is distributed on an "AS IS" BASIS,
 WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 See the License for the specific language governing permissions and
 limitations under the License.
 .
 On Debian systems, the complete text of the Apache version 2.0 license
 can be found in "/usr/share/common-licenses/Apache-2.0".

License: BSD-2-Clause
 Redistribution and use in source and binary forms, with or without
 modification, are permitted provided that the following conditions are met:

 1. Redistributions of source code must retain the above copyright notice,
   this list of conditions and the following disclaimer.

 2. Redistributions in binary form must reproduce the above copyright
   notice, this list of conditions and the following disclaimer in the
   documentation and/or other materials provided with the distribution.

 THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
 AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
 ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
 LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
 CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
 SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
 INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
 CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
 ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
 POSSIBILITY OF SUCH DAMAGE.

Review Information

accepted — allocated to awm 30 days ago, started 30 days ago, completed 30 days ago.

Final Comment

Hi,

In the debian/copyright some lines are missing the continuation '.', notably in the BSD-2-Clause license description.

Thanks!

Public Notes

30 days ago ● public

Lintian

Command: lintian -Iiv -L '>=warning' --show-overrides --color=never ../$(basename $PWD)_*.changes
Exit code: 0

N:
W: python3-xgrammar: debian-changelog-line-too-long [usr/share/doc/python3-xgrammar/changelog.Debian.gz:8]
N: 
N:   The given line of the latest changelog entry is over 80 columns. Such
N:   changelog entries may look poor in terminal windows and mail messages and
N:   be annoying to read. Please wrap changelog entries at 80 columns or less
N:   where possible.
N: 
N:   Visibility: warning
N:   Show-Always: no
N:   Check: debian/changelog
N: 
N:
W: python3-xgrammar: initial-upload-closes-no-bugs [usr/share/doc/python3-xgrammar/changelog.Debian.gz:1]
N: 
N:   This package appears to be the first packaging of a new upstream software
N:   package (there is only one changelog entry and the Debian revision is 1),
N:   but it does not close any bugs. The initial upload of a new package should
N:   close the corresponding ITP bug for that package.
N:   
N:   This warning can be ignored if the package is not intended for Debian or
N:   if it is a split of an existing Debian package.
N: 
N:   Please refer to New packages (Section 5.1) in the Debian Developer's
N:   Reference for details.
N: 
N:   Visibility: warning
N:   Show-Always: no
N:   Check: debian/changelog
N:   Renamed from: new-package-should-close-itp-bug
N: 
N:
W: xgrammar source: syntax-error-in-dep5-copyright Continuation line not in paragraph (line 48). Missing a dot on the previous line? [debian/copyright]
N: 
N:   The machine-readable copyright file didn't pass Debian control file syntax
N:   check.
N:   
N:   This issue may hide other issues as Lintian skips some checks on the file
N:   in this case.
N: 
N:   Please refer to
N:   https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/ for
N:   details.
N: 
N:   Visibility: warning
N:   Show-Always: no
N:   Check: debian/copyright/dep5
N: 

Back to Dashboard | View all reviews for this package