DFSG NEW Queue

DFSG, Licensing & New Packages Team

Review: yq-go 4.53.2-2

New Package Report

.changes
Changed-ByChristoph Martin
Architecturesource amd64
Distributionexperimental
DateWed, 13 May 2026 00:27:02 +0200
Sourceyq-go
Version4.53.2-2
Changelog
yq-go (4.53.2-2) experimental; urgency=medium
 .
   * close ITP (Closes: 1135905, 1062445)
   * update copyright file
.dsc
Sectionutils
Priorityoptional
Componentmain
Package-Listyq-go deb utils optional arch=any
debian/copyright
Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Source: https://github.com/mikefarah/yq
Upstream-Name: yq

Files: *
Copyright: Copyright (c) 2017 Mike Farah
License: Expat

Files: scripts/shunit2
Copyright: Kate Ward (2008-2020)
License: Apache-2.0
 The license can be found in /usr/share/common-licenses/Apache-2.0.

Files: scripts/release-deb.sh
Copyright: Roberto Mier Escandón (2021)
License: Expat

Files: debian/*
Copyright: 2026 Christoph Martin <chrism@debian.org>
License: Expat
Comment: Debian packaging is licensed under the same terms as upstream

License: Expat
 Permission is hereby granted, free of charge, to any person obtaining
 a copy of this software and associated documentation files (the
 "Software"), to deal in the Software without restriction, including
 without limitation the rights to use, copy, modify, merge, publish,
 distribute, sublicense, and/or sell copies of the Software, and to
 permit persons to whom the Software is furnished to do so, subject to
 the following conditions:
 .
 The above copyright notice and this permission notice shall be included
 in all copies or substantial portions of the Software.
 .
 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
 EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
 MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.
 IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY
 CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT,
 TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE
 SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Review Information

rejected — allocated to siretart 16 days ago, started 16 days ago, completed 16 days ago.

Final Comment

Thanks for your diligence in bringing yq-go to the archive. I've
had another look through the source, and while it's mostly there,
I have to reject it for now because of a few minor metadata and
policy issues.

I noticed a slight slip in the way copyright statements are handled
in debian/copyright. The statements need to be reproduced
verbatim from the source headers to accurately reflect the upstream
notices. For instance, the notice for scripts/shunit2 should
include the "All Rights Reserved" portion, and the entry for
scripts/release-deb.sh should match the exact format of the
header, including the (C) symbol and email address.

This is also a bit of a DFSG problem regarding the embedded copy of
the shunit2 framework in scripts/shunit2. While it is correctly
licensed, Debian Policy §4.13 generally prefers using the packaged
version from the archive. If you find it necessary to bundle it,
please include a debian/README.source file that documents this
embedded copy and explains why the system-wide package isn't being
used instead.

Lastly, there are some formatting bits in the copyright file to
clean up. The Apache-2.0 license should have its own standalone
stanza at the bottom of the file that points to the common
licenses directory, rather than having the reference nested inside
the file stanza. I also noticed that the License: Expat string is
repeated as the first line of the license text block in the main
stanza, which should be removed.

Once these bits are polished, it should be ready for another look.

-rt

Other Reviews of this Package

VersionHashAllocatedCompletedReviewerStatusDetails
4.53.2+ds-1 1f0bf711… 2026-05-18 11:27 2026-05-18 11:36 siretart accepted VIEW
4.53.2-1 37c8955d… 2026-05-12 12:58 2026-05-12 13:12 siretart rejected VIEW
4.53.2-1 4f3ebe3d… 2026-05-13 09:38 2026-05-13 10:12 siretart rejected VIEW

Back to Dashboard | View all reviews for this package