docs: add Flutter license triage evidence
This commit is contained in:
@@ -9,12 +9,21 @@ The generator performs local JSON and uniqueness checks; this snapshot has not y
|
||||
- 50 Python distributions from `.venv`: 8 direct runtime requirements, 1 optional OCR requirement, and 41 installed transitive/development packages. Python versions are the versions installed in this local environment; `requirements.txt` still uses ranges and is not a fully pinned production lock.
|
||||
- 104 Flutter pub packages from the resolved lock: 15 direct main, 3 direct development, and 86 transitive/SDK packages.
|
||||
- 104 package license files have SHA-256 evidence. For 101 components the inventory can find a license file but deliberately does not classify its legal terms automatically. The remaining declarations come from distribution/package metadata or the Flutter SDK license notice.
|
||||
- A separate text-signature triage report is generated at `flutter-license-triage.json`. At this snapshot it found 102 package license files directly in resolved package roots: 98 have a single recognizable candidate signature (78 BSD-3-Clause, 16 MIT, 3 Apache-2.0, and 1 BSD-2-Clause), 1 has an MPL-2.0 signature, and 3 remain ambiguous/unclassified; 2 SDK packages have no package-root license file. These are **candidates only**, not legal classifications. Every item still needs a reviewer to confirm the package's declared terms, source and included notices; the counts do not replace the 104-file hash evidence in the main inventory.
|
||||
- The Windows Debug artifact bundled `NOTICES.Z` (SHA-256 `eb0096c70ca8a2b23d1a806f1fddb5ce379730712347b267b7c7de4599b8ba70`; 1,836,646 bytes after decompression). The application build already carries this Flutter notice archive.
|
||||
- Three host-local runtime artifacts are now hashed as CycloneDX file/model components. `pypdfium2` 5.13.0's `pdfium.dll` is 7,260,672 bytes (SHA-256 `fb898a1f5ace57805834f390407500bdb6ef93eff326a252ad334a8aae809d8e`); the inventory records hashes for 16 Windows x64 `BUILD_LICENSES` files shipped in the wheel.
|
||||
- EasyOCR 1.7.2's local `arabic.pth` (215,400,714 bytes; SHA-256 `2a9afd42c374deb98aed0b53c9b77d75e1d00d4e0501f3b0276c54190c89b1a8`) and `craft_mlt_25k.pth` (83,152,330 bytes; SHA-256 `4a5efbfb48b4081100544e75e1e2b57f8de3d84f213004b14b85fd4b3748db17`) match the MD5 identifiers in the pinned EasyOCR model configuration. This confirms artifact identity against that manifest, not redistribution rights; both model components remain marked for human license review. `english_g2.pth`, which the current Arabic/English reader expects, is absent from this host's OCR model directory and is recorded as missing. The OCR code may download it when first initializing because downloads are enabled by default.
|
||||
|
||||
The inventory does not include dependency edges, a release-only Python environment, all native Windows/C++ components, or completed classification of PDFium/OCR notices. It does not decide whether any license permits a specific commercial distribution. Continue the manual source, hash, notice, and terms review in `LICENSE_REVIEW_2026-10.md` for the exact release artifacts.
|
||||
|
||||
The Flutter candidate report can be regenerated from the repository root with:
|
||||
|
||||
```powershell
|
||||
& .\.venv\Scripts\python.exe .\scripts\generate_flutter_license_triage.py
|
||||
```
|
||||
|
||||
It uses only local lockfile/package-cache files and SHA-256 hashes. A missing or ambiguous entry must remain unresolved until reviewed against its package and upstream terms.
|
||||
|
||||
## Regenerate
|
||||
|
||||
From the repository root, after installing Python requirements in `.venv` and resolving Flutter packages:
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user