# OpenCode task: build a conservative Flutter license evidence scan ## Goal Create a repeatable, local-only screening report for the Flutter packages currently listed in `sbom/component-inventory.json`. The inventory already stores SHA-256 hashes for 104 Flutter license files, while 101 are deliberately left unclassified. Reduce manual triage by detecting likely standard license text without treating a text match as a legal conclusion. ## Read first - `LICENSE_REVIEW_2026-10.md` - `sbom/README.md` - `sbom/component-inventory.json` - `scripts/generate_component_inventory.py` - `tests/test_component_inventory.py` - `flutter_app/pubspec.lock` and `.dart_tool/package_config.json` ## Deliverables 1. Add a deterministic Python script that reads the existing inventory and the resolved Pub package cache, verifies each source license file against its recorded SHA-256, and emits one record per eligible package. 2. Detect only conservative license-text candidates (for example MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, and MPL-2.0). Include the literal matched evidence phrase, source filename/hash, package/version, and a status such as `candidate_requires_human_review`. 3. Mark composite, bundled, missing, modified, or ambiguous texts as `unclassified` rather than guessing. Never infer a package's legal grant from the license title alone, and never promote a candidate to an approved SPDX license in the current SBOM. 4. Add tests for supported candidates, ambiguous/composite text, unknown text, and hash mismatch. Use only temporary directories inside the test fixture root. 5. Add a generated screening artifact and explain its limits in `sbom/README.md`; update `ROADMAP.md` with counts and verification evidence. Do not mark commercial approval complete. ## Constraints - Work only in this repository and keep the installed-package inventory unchanged unless its schema needs a documented, tested extension. - Do not access the network, install packages, change user/global configuration, or inspect secrets. - Do not edit model licenses, OCR weights, Groq terms, or native Windows/PDFium conclusions in this task. - Do not commit or push. Report changed paths, checks run, candidate/unclassified counts, and any blocker.