Files
sovereign_ai/SovereignAI-Starter/sbom

Preliminary component inventory

component-inventory.json is a point-in-time CycloneDX 1.5 inventory assembled from the active Python virtual environment, flutter_app/pubspec.lock, the installed PDFium native binary and its wheel-bundled build notices, observed local EasyOCR model weights, and (when supplied) the bundled Flutter NOTICES.Z file. Host-local runtime files are observations for the current machine, not a release artifact manifest. This is an engineering aid, not a complete or legally approved commercial SBOM.

The generator performs local JSON and uniqueness checks; this snapshot has not yet been validated against the official CycloneDX 1.5 JSON schema. The pub PURL type is listed by the Package-URL type registry.

Snapshot captured on 2026-10-07

  • 50 Python distributions from .venv: 8 direct runtime requirements, 1 optional OCR requirement, and 41 installed transitive/development packages. Python versions are the versions installed in this local environment; requirements.txt still uses ranges and is not a fully pinned production lock.
  • 104 Flutter pub packages from the resolved lock: 15 direct main, 3 direct development, and 86 transitive/SDK packages.
  • 104 package license files have SHA-256 evidence. For 101 components the inventory can find a license file but deliberately does not classify its legal terms automatically. The remaining declarations come from distribution/package metadata or the Flutter SDK license notice.
  • A separate text-signature triage report is generated at flutter-license-triage.json. At this snapshot it found 102 package license files directly in resolved package roots: 99 have a single recognizable candidate signature (78 BSD-3-Clause, 16 MIT, 3 Apache-2.0, 1 BSD-2-Clause, and 1 MPL-2.0); 3 files are composite notices with multiple signatures, including file_selector_android, url_launcher_web, and the Flutter sky_engine bundle. Two SDK packages have no package-root license file. The report also lists detected signatures in composite files without assigning them to a specific bundled component. These are candidates only, not legal classifications. Every item still needs a reviewer to confirm the package's declared terms, source and included notices; the counts do not replace the 104-file hash evidence in the main inventory.
  • The Windows Debug artifact bundled NOTICES.Z (SHA-256 eb0096c70ca8a2b23d1a806f1fddb5ce379730712347b267b7c7de4599b8ba70; 1,836,646 bytes after decompression). The application build already carries this Flutter notice archive.
  • Three host-local runtime artifacts are now hashed as CycloneDX file/model components. pypdfium2 5.13.0's pdfium.dll is 7,260,672 bytes (SHA-256 fb898a1f5ace57805834f390407500bdb6ef93eff326a252ad334a8aae809d8e); the inventory records hashes for 16 Windows x64 BUILD_LICENSES files shipped in the wheel.
  • EasyOCR 1.7.2's local arabic.pth (215,400,714 bytes; SHA-256 2a9afd42c374deb98aed0b53c9b77d75e1d00d4e0501f3b0276c54190c89b1a8) and craft_mlt_25k.pth (83,152,330 bytes; SHA-256 4a5efbfb48b4081100544e75e1e2b57f8de3d84f213004b14b85fd4b3748db17) match the MD5 identifiers in the pinned EasyOCR model configuration. This confirms artifact identity against that manifest, not redistribution rights; both model components remain marked for human license review. english_g2.pth, which the current Arabic/English reader expects, is absent from this host's OCR model directory and is recorded as missing. The OCR code may download it when first initializing because downloads are enabled by default.

The inventory does not include dependency edges, a release-only Python environment, all native Windows/C++ components, or completed classification of PDFium/OCR notices. It does not decide whether any license permits a specific commercial distribution. Continue the manual source, hash, notice, and terms review in LICENSE_REVIEW_2026-10.md for the exact release artifacts.

The Flutter candidate report can be regenerated from the repository root with:

& .\.venv\Scripts\python.exe .\scripts\generate_flutter_license_triage.py

It uses only local lockfile/package-cache files and SHA-256 hashes. A missing or ambiguous entry must remain unresolved until reviewed against its package and upstream terms.

Regenerate

From the repository root, after installing Python requirements in .venv and resolving Flutter packages:

& .\.venv\Scripts\python.exe .\scripts\generate_component_inventory.py

To hash the notices archive from a Windows build, add --flutter-notices <path-to-NOTICES.Z>. The script reads installed Python distribution metadata, the Flutter lock and package cache, the installed pypdfium2_raw binary and its license notices, the three EasyOCR model files from LOCAL_OCR_MODEL_DIR (or the app's default model directory), and the passed Flutter notice archive. It does not install packages, download models, or infer that a detected file is legally redistributable.