Files
sovereign_ai/SovereignAI-Starter/sbom/README.md
T

2.5 KiB

Preliminary component inventory

component-inventory.json is a point-in-time CycloneDX 1.5 inventory assembled from the active Python virtual environment, flutter_app/pubspec.lock, and (when supplied) the bundled Flutter NOTICES.Z file. It is an engineering aid, not a complete or legally approved commercial SBOM.

The generator performs local JSON and uniqueness checks; this snapshot has not yet been validated against the official CycloneDX 1.5 JSON schema. The pub PURL type is listed by the Package-URL type registry.

Snapshot captured on 2026-10-04

  • 50 Python distributions from .venv: 8 direct runtime requirements, 1 optional OCR requirement, and 41 installed transitive/development packages. Python versions are the versions installed in this local environment; requirements.txt still uses ranges and is not a fully pinned production lock.
  • 104 Flutter pub packages from the resolved lock: 15 direct main, 3 direct development, and 86 transitive/SDK packages.
  • 104 package license files have SHA-256 evidence. For 101 components the inventory can find a license file but deliberately does not classify its legal terms automatically. The remaining declarations come from distribution/package metadata or the Flutter SDK license notice.
  • The Windows Debug artifact bundled NOTICES.Z (SHA-256 eb0096c70ca8a2b23d1a806f1fddb5ce379730712347b267b7c7de4599b8ba70; 1,836,646 bytes after decompression). The application build already carries this Flutter notice archive.

The inventory does not include dependency edges, a release-only Python environment, all native Windows/C++ components, a complete PDFium notice review, OCR model-weight files, or model weights. It does not decide whether any license permits a specific commercial distribution. Continue the manual source, hash, notice, and terms review in LICENSE_REVIEW_2026-10.md for the exact release artifacts.

Regenerate

From the repository root, after installing Python requirements in .venv and resolving Flutter packages:

& .\.venv\Scripts\python.exe .\scripts\generate_component_inventory.py

To hash the notices archive from a Windows build, add --flutter-notices <path-to-NOTICES.Z>. The script reads installed Python distribution metadata, the Flutter lock and package cache, and the passed notice archive; it does not install packages or inspect model weights.