#1101715 RFS: libxchange/1.0.0-1 [ITP] -- Structured data representation and JSON support for C/C++

#1101715#5
Date:
2025-03-30 20:52:43 UTC
From:
To:
Package: sponsorship-requests
Severity: wishlist

Dear mentors,

I am looking for a sponsor for my package "libxchange":

  * Package name     : libxchange
    Version          : 1.0.0-1
    Upstream contact : Attila Kovacs <attila.kovacs@cfa.harvard.edu>
  * URL              : https://smithsonian.github.io/xchange
  * License          : Unlicense
  * Vcs              : https://salsa.debian.org/attipaci/libxchange
    Section          : devel

The source builds the following binary packages:

   libxchange1 - Structured data representation and JSON support for C/C++
   libxchange-dev - C development files for the xchange C/C++ library
   libxchange-doc - Documentation for the xchange C/C++ library

To access further information about this package, please visit the
following URL:

   https://mentors.debian.net/package/libxchange/

Alternatively, you can download the package with 'dget' using this command:

   dget -x
https://mentors.debian.net/debian/pool/main/libx/libxchange/libxchange_1.0.0-1.dsc

Changes for the initial release:

  libxchange (1.0.0-1) UNRELEASED; urgency=medium
  .
    * Upstream v1.0.0
    * Initial debian files
    * Initial release (Closes: #1100352)

Regards,

#1101715#12
Date:
2025-03-31 10:05:05 UTC
From:
To:
Attila,

Review of upload: 2025-03-30 21:41

For information about the tests run, see:

https://wiki.debian.org/PhilWyett/DebianMentoring

Test 4 (sbuild): Information only

lintian:

I offer the full output for information that you may wish to look at.

Running lintian...
N:
E: libxchange changes: unreleased-changes
N:
N:   The distribution in the Changes field copied from debian/changelog
N:   indicates that this package was not intended to be released yet.
N:
N:   Please refer to Bug#542747 for details.
N:
N:   Visibility: error
N:   Show-Always: no
N:   Check: fields/distribution
N:
N:
W: libxchange-doc: duplicate-changelog-files usr/share/doc/libxchange-
dev/html/md_CHANGELOG.html usr/share/doc/libxchange-
dev/libxchange/html/md_CHANGELOG.html
N:
N:   The package appears to be shipping two copies of the changelog.
N:
N:   If the second copy is really needed, consider making it a symlink to the
N:   canonical place for the relevant changelog.
N:
N:   Both upstream and Debian changelogs are checked with this tag.
N:
N:   Visibility: warning
N:   Show-Always: no
N:   Check: files/duplicates
N:
N:
W: libxchange-doc: privacy-breach-generic [<img
src="https://zenodo.org/badge/796202092.svg" alt="doi" style="pointer-events:
none;" class="inline"/>] (https://zenodo.org/badge/796202092.svg)
[usr/share/doc/libxchange-dev/html/index.html]
N:
N:   This package creates a potential privacy breach by fetching data from an
N:   external website at runtime. Please remove these scripts or external HTML
N:   resources.
N:
N:   Please replace any scripts, images, or other remote resources with
N:   non-remote resources. It is preferable to replace them with text and links
N:   but local copies of the remote resources are also acceptable as long as
N:   they don't also make calls to remote services. Please ensure that the
N:   remote resources are suitable for Debian main before making local copies
N:   of them.
N:
N:   Visibility: warning
N:   Show-Always: no
N:   Check: files/privacy-breach
N:
N:
W: libxchange-doc: privacy-breach-generic [<img
src="https://zenodo.org/badge/796202092.svg" alt="doi" style="pointer-events:
none;" class="inline"/>] (https://zenodo.org/badge/796202092.svg)
[usr/share/doc/libxchange-dev/libxchange/html/index.html]
N:
P: libxchange source: trailing-whitespace [debian/control:20]
N:
N:   This file contains lines with trailing whitespace characters.
N:
N:   Whilst often harmless and unsightly, such extra whitespaces can also cause
N:   tools to interpret the whitespace characters literally. The tool diff(1)
N:   does not like them, either. They are best avoided.
N:
N:   Some of these problems can be hard to track down.
N:
N:   Whitespace at the end of lines may be removed with the following:
N:
N:    $ sed -i -e 's@[[:space:]]*$@@g' debian/control debian/changelog
N:
N:   If you use Emacs, you can also use "M-x wh-cl" (whitespace-cleanup).
N:
N:   However, if you wish to only remove trailing spaces and leave trailing
N:   tabs (eg. for Makefiles), you can use the following code snippet:
N:
N:    $ sed -i -e 's@[ ]*$@@g' debian/rules
N:
N:   To remove empty lines from the end of a file, you can use:
N:
N:    $ sed -i -e :a -e '/^\n*$/{$d;N;};/\n$/ba' debian/rules
N:
N:   Visibility: pedantic
N:   Show-Always: no
N:   Check: debian/trailing-whitespace
N:   Renamed from: file-contains-trailing-whitespace
N:
N:
P: libxchange source: trailing-whitespace [debian/control:43]

E: Lintian run failed (runtime error)

Summary
=======

Attila, Package is looking promising.

* Can you target a distribution i.e. unstable or experimental in
'debian/changelog'?

* As a new package to Debian we really only need the third line of your
'debian/changelog'. Would you be able to remove lines one and two?

#1101715#17
Date:
2025-03-31 10:05:05 UTC
From:
To:
Attila,

Review of upload: 2025-03-30 21:41

For information about the tests run, see:

https://wiki.debian.org/PhilWyett/DebianMentoring

Test 4 (sbuild): Information only

lintian:

I offer the full output for information that you may wish to look at.

Running lintian...
N:
E: libxchange changes: unreleased-changes
N:
N:   The distribution in the Changes field copied from debian/changelog
N:   indicates that this package was not intended to be released yet.
N:
N:   Please refer to Bug#542747 for details.
N:
N:   Visibility: error
N:   Show-Always: no
N:   Check: fields/distribution
N:
N:
W: libxchange-doc: duplicate-changelog-files usr/share/doc/libxchange-
dev/html/md_CHANGELOG.html usr/share/doc/libxchange-
dev/libxchange/html/md_CHANGELOG.html
N:
N:   The package appears to be shipping two copies of the changelog.
N:
N:   If the second copy is really needed, consider making it a symlink to the
N:   canonical place for the relevant changelog.
N:
N:   Both upstream and Debian changelogs are checked with this tag.
N:
N:   Visibility: warning
N:   Show-Always: no
N:   Check: files/duplicates
N:
N:
W: libxchange-doc: privacy-breach-generic [<img
src="https://zenodo.org/badge/796202092.svg" alt="doi" style="pointer-events:
none;" class="inline"/>] (https://zenodo.org/badge/796202092.svg)
[usr/share/doc/libxchange-dev/html/index.html]
N:
N:   This package creates a potential privacy breach by fetching data from an
N:   external website at runtime. Please remove these scripts or external HTML
N:   resources.
N:
N:   Please replace any scripts, images, or other remote resources with
N:   non-remote resources. It is preferable to replace them with text and links
N:   but local copies of the remote resources are also acceptable as long as
N:   they don't also make calls to remote services. Please ensure that the
N:   remote resources are suitable for Debian main before making local copies
N:   of them.
N:
N:   Visibility: warning
N:   Show-Always: no
N:   Check: files/privacy-breach
N:
N:
W: libxchange-doc: privacy-breach-generic [<img
src="https://zenodo.org/badge/796202092.svg" alt="doi" style="pointer-events:
none;" class="inline"/>] (https://zenodo.org/badge/796202092.svg)
[usr/share/doc/libxchange-dev/libxchange/html/index.html]
N:
P: libxchange source: trailing-whitespace [debian/control:20]
N:
N:   This file contains lines with trailing whitespace characters.
N:
N:   Whilst often harmless and unsightly, such extra whitespaces can also cause
N:   tools to interpret the whitespace characters literally. The tool diff(1)
N:   does not like them, either. They are best avoided.
N:
N:   Some of these problems can be hard to track down.
N:
N:   Whitespace at the end of lines may be removed with the following:
N:
N:    $ sed -i -e 's@[[:space:]]*$@@g' debian/control debian/changelog
N:
N:   If you use Emacs, you can also use "M-x wh-cl" (whitespace-cleanup).
N:
N:   However, if you wish to only remove trailing spaces and leave trailing
N:   tabs (eg. for Makefiles), you can use the following code snippet:
N:
N:    $ sed -i -e 's@[ ]*$@@g' debian/rules
N:
N:   To remove empty lines from the end of a file, you can use:
N:
N:    $ sed -i -e :a -e '/^\n*$/{$d;N;};/\n$/ba' debian/rules
N:
N:   Visibility: pedantic
N:   Show-Always: no
N:   Check: debian/trailing-whitespace
N:   Renamed from: file-contains-trailing-whitespace
N:
N:
P: libxchange source: trailing-whitespace [debian/control:43]

E: Lintian run failed (runtime error)

Summary
=======

Attila, Package is looking promising.

* Can you target a distribution i.e. unstable or experimental in
'debian/changelog'?

* As a new package to Debian we really only need the third line of your
'debian/changelog'. Would you be able to remove lines one and two?

#1101715#22
Date:
2025-03-31 19:09:10 UTC
From:
To:
Hi Phil,


Thanks for the quick review.

I have updated the changelog to target for unstable, and with the single
entry that closes the ITP. I've replaced the upload on mentors with the
new package.

I did also look at the warnings from your checks. The external link is
to a Zenodo DOI badge in the docs. I will replace that with a local copy
for the next upstream release. As for the duplicate upstream CHANGELOG,
I think it's a small inconvenience that is best left as is. Doxygen
copies the upstream CHANGELOG when ingesting it for the HTML
documentation for the doc subpackage. But, it's not a huge file (nor
ever going to be more than a few kB), so it's probably best not to
tinker with.

Let me know if there is anything else still outstanding.

And thank you for sponsoring!

#1101715#27
Date:
2025-04-01 17:10:11 UTC
From:
To:
Control: tags -1 -moreinfo
Control: tags -1 +confirmed

Attila,

Many thanks for making improvements in the package. I will tag the package as
'confirmed' and hope a DD can find free time soon to review the package and
possibly upload to Debian.

#1101715#36
Date:
2025-05-10 08:38:26 UTC
From:
To:
Attila,

Review of upload: 2025-03-31 18:56

For information about the tests run, see:

https://wiki.debian.org/PhilWyett/DebianMentoring

Test 4 (sbuild): Information only

Lintian:

Running lintian...
N:
W: libxchange-doc: duplicate-changelog-files usr/share/doc/libxchange-
dev/html/md_CHANGELOG.html usr/share/doc/libxchange-
dev/libxchange/html/md_CHANGELOG.html
N:
N:   The package appears to be shipping two copies of the changelog.
N:
N:   If the second copy is really needed, consider making it a symlink to the
N:   canonical place for the relevant changelog.
N:
N:   Both upstream and Debian changelogs are checked with this tag.
N:
N:   Visibility: warning
N:   Show-Always: no
N:   Check: files/duplicates
N:
N:
W: libxchange-doc: privacy-breach-generic [<img
src="https://zenodo.org/badge/796202092.svg" alt="doi" style="pointer-events:
none;" class="inline"/>] (https://zenodo.org/badge/796202092.svg)
[usr/share/doc/libxchange-dev/html/index.html]
N:
N:   This package creates a potential privacy breach by fetching data from an
N:   external website at runtime. Please remove these scripts or external HTML
N:   resources.
N:
N:   Please replace any scripts, images, or other remote resources with
N:   non-remote resources. It is preferable to replace them with text and links
N:   but local copies of the remote resources are also acceptable as long as
N:   they don't also make calls to remote services. Please ensure that the
N:   remote resources are suitable for Debian main before making local copies
N:   of them.
N:
N:   Visibility: warning
N:   Show-Always: no
N:   Check: files/privacy-breach
N:
N:
W: libxchange-doc: privacy-breach-generic [<img
src="https://zenodo.org/badge/796202092.svg" alt="doi" style="pointer-events:
none;" class="inline"/>] (https://zenodo.org/badge/796202092.svg)
[usr/share/doc/libxchange-dev/libxchange/html/index.html]
N:
P: libxchange source: trailing-whitespace [debian/control:20]
N:
N:   This file contains lines with trailing whitespace characters.
N:
N:   Whilst often harmless and unsightly, such extra whitespaces can also cause
N:   tools to interpret the whitespace characters literally. The tool diff(1)
N:   does not like them, either. They are best avoided.
N:
N:   Some of these problems can be hard to track down.
N:
N:   Whitespace at the end of lines may be removed with the following:
N:
N:    $ sed -i -e 's@[[:space:]]*$@@g' debian/control debian/changelog
N:
N:   If you use Emacs, you can also use "M-x wh-cl" (whitespace-cleanup).
N:
N:   However, if you wish to only remove trailing spaces and leave trailing
N:   tabs (eg. for Makefiles), you can use the following code snippet:
N:
N:    $ sed -i -e 's@[ ]*$@@g' debian/rules
N:
N:   To remove empty lines from the end of a file, you can use:
N:
N:    $ sed -i -e :a -e '/^\n*$/{$d;N;};/\n$/ba' debian/rules
N:
N:   Visibility: pedantic
N:   Show-Always: no
N:   Check: debian/trailing-whitespace
N:   Renamed from: file-contains-trailing-whitespace
N:
N:
P: libxchange source: trailing-whitespace [debian/control:43]

E: Lintian run failed (policy violation)

Test 6 (debian/watch): Information only

philwyett@ks-tarkin:~/Development/builder/debian/libxchange-1.0.0$ uscan --dehs
<dehs>
Newest version of libxchange on remote site is 1.0.1~rc1, local version is 1.0.0
 => Newer package available from:
        =>
https://github.com/Smithsonian/xchange/archive/refs/tags/v1.0.1-rc1.tar.gz
Successfully renamed ../xchange-1.0.1-rc1.tar.gz to
../libxchange_1.0.1~rc1.orig.tar.gz.
<package>libxchange</package>
<debian-uversion>1.0.0</debian-uversion>
<debian-mangled-uversion>1.0.0</debian-mangled-uversion>
<upstream-version>1.0.1~rc1</upstream-version>
<upstream-
url>https://github.com/Smithsonian/xchange/archive/refs/tags/v1.0.1-rc1.tar.gz</
upstream-url>
<status>newer package available</status>
<target>libxchange_1.0.1~rc1.orig.tar.gz</target>
<target-path>../libxchange_1.0.1~rc1.orig.tar.gz</target-path>
<messages>Successfully downloaded upstream package: v1.0.1-rc1.tar.gz

</messages>
<messages>Renamed upstream package to: xchange-1.0.1-rc1.tar.gz

</messages>
</dehs>

Summary
=======

Updated review with newer tools, but still the sole reviewer on Mentors. I am
extremely sorry the package has languished on Debian Mentors do long.

Test 4.

Please consider reviewing and possibly fixing one or more of the lintian issues
raised.

Test 6.

A nwere upstream version is available. You could consider packaging it or
rewrite 'debian/watch' to highlight 'releases' only and not everything that is
tagged.

#1101715#43
Date:
2025-05-10 08:38:26 UTC
From:
To:
Attila,

Review of upload: 2025-03-31 18:56

For information about the tests run, see:

https://wiki.debian.org/PhilWyett/DebianMentoring

Test 4 (sbuild): Information only

Lintian:

Running lintian...
N:
W: libxchange-doc: duplicate-changelog-files usr/share/doc/libxchange-
dev/html/md_CHANGELOG.html usr/share/doc/libxchange-
dev/libxchange/html/md_CHANGELOG.html
N:
N:   The package appears to be shipping two copies of the changelog.
N:
N:   If the second copy is really needed, consider making it a symlink to the
N:   canonical place for the relevant changelog.
N:
N:   Both upstream and Debian changelogs are checked with this tag.
N:
N:   Visibility: warning
N:   Show-Always: no
N:   Check: files/duplicates
N:
N:
W: libxchange-doc: privacy-breach-generic [<img
src="https://zenodo.org/badge/796202092.svg" alt="doi" style="pointer-events:
none;" class="inline"/>] (https://zenodo.org/badge/796202092.svg)
[usr/share/doc/libxchange-dev/html/index.html]
N:
N:   This package creates a potential privacy breach by fetching data from an
N:   external website at runtime. Please remove these scripts or external HTML
N:   resources.
N:
N:   Please replace any scripts, images, or other remote resources with
N:   non-remote resources. It is preferable to replace them with text and links
N:   but local copies of the remote resources are also acceptable as long as
N:   they don't also make calls to remote services. Please ensure that the
N:   remote resources are suitable for Debian main before making local copies
N:   of them.
N:
N:   Visibility: warning
N:   Show-Always: no
N:   Check: files/privacy-breach
N:
N:
W: libxchange-doc: privacy-breach-generic [<img
src="https://zenodo.org/badge/796202092.svg" alt="doi" style="pointer-events:
none;" class="inline"/>] (https://zenodo.org/badge/796202092.svg)
[usr/share/doc/libxchange-dev/libxchange/html/index.html]
N:
P: libxchange source: trailing-whitespace [debian/control:20]
N:
N:   This file contains lines with trailing whitespace characters.
N:
N:   Whilst often harmless and unsightly, such extra whitespaces can also cause
N:   tools to interpret the whitespace characters literally. The tool diff(1)
N:   does not like them, either. They are best avoided.
N:
N:   Some of these problems can be hard to track down.
N:
N:   Whitespace at the end of lines may be removed with the following:
N:
N:    $ sed -i -e 's@[[:space:]]*$@@g' debian/control debian/changelog
N:
N:   If you use Emacs, you can also use "M-x wh-cl" (whitespace-cleanup).
N:
N:   However, if you wish to only remove trailing spaces and leave trailing
N:   tabs (eg. for Makefiles), you can use the following code snippet:
N:
N:    $ sed -i -e 's@[ ]*$@@g' debian/rules
N:
N:   To remove empty lines from the end of a file, you can use:
N:
N:    $ sed -i -e :a -e '/^\n*$/{$d;N;};/\n$/ba' debian/rules
N:
N:   Visibility: pedantic
N:   Show-Always: no
N:   Check: debian/trailing-whitespace
N:   Renamed from: file-contains-trailing-whitespace
N:
N:
P: libxchange source: trailing-whitespace [debian/control:43]

E: Lintian run failed (policy violation)

Test 6 (debian/watch): Information only

philwyett@ks-tarkin:~/Development/builder/debian/libxchange-1.0.0$ uscan --dehs
<dehs>
Newest version of libxchange on remote site is 1.0.1~rc1, local version is 1.0.0
 => Newer package available from:
        =>
https://github.com/Smithsonian/xchange/archive/refs/tags/v1.0.1-rc1.tar.gz
Successfully renamed ../xchange-1.0.1-rc1.tar.gz to
../libxchange_1.0.1~rc1.orig.tar.gz.
<package>libxchange</package>
<debian-uversion>1.0.0</debian-uversion>
<debian-mangled-uversion>1.0.0</debian-mangled-uversion>
<upstream-version>1.0.1~rc1</upstream-version>
<upstream-
url>https://github.com/Smithsonian/xchange/archive/refs/tags/v1.0.1-rc1.tar.gz</
upstream-url>
<status>newer package available</status>
<target>libxchange_1.0.1~rc1.orig.tar.gz</target>
<target-path>../libxchange_1.0.1~rc1.orig.tar.gz</target-path>
<messages>Successfully downloaded upstream package: v1.0.1-rc1.tar.gz

</messages>
<messages>Renamed upstream package to: xchange-1.0.1-rc1.tar.gz

</messages>
</dehs>

Summary
=======

Updated review with newer tools, but still the sole reviewer on Mentors. I am
extremely sorry the package has languished on Debian Mentors do long.

Test 4.

Please consider reviewing and possibly fixing one or more of the lintian issues
raised.

Test 6.

A nwere upstream version is available. You could consider packaging it or
rewrite 'debian/watch' to highlight 'releases' only and not everything that is
tagged.