Files
sovereign_ai/SovereignAI-Starter/sbom/README.md
T

25 lines
2.5 KiB
Markdown

# Preliminary component inventory
`component-inventory.json` is a point-in-time CycloneDX 1.5 inventory assembled from the active Python virtual environment, `flutter_app/pubspec.lock`, and (when supplied) the bundled Flutter `NOTICES.Z` file. It is an engineering aid, not a complete or legally approved commercial SBOM.
The generator performs local JSON and uniqueness checks; this snapshot has not yet been validated against the official [CycloneDX 1.5 JSON schema](https://github.com/CycloneDX/specification/blob/master/schema/bom-1.5.schema.json). The `pub` PURL type is listed by the [Package-URL type registry](https://github.com/package-url/purl-spec/blob/main/purl-types-index.json).
## Snapshot captured on 2026-10-04
- 50 Python distributions from `.venv`: 8 direct runtime requirements, 1 optional OCR requirement, and 41 installed transitive/development packages. Python versions are the versions installed in this local environment; `requirements.txt` still uses ranges and is not a fully pinned production lock.
- 104 Flutter pub packages from the resolved lock: 15 direct main, 3 direct development, and 86 transitive/SDK packages.
- 104 package license files have SHA-256 evidence. For 101 components the inventory can find a license file but deliberately does not classify its legal terms automatically. The remaining declarations come from distribution/package metadata or the Flutter SDK license notice.
- The Windows Debug artifact bundled `NOTICES.Z` (SHA-256 `eb0096c70ca8a2b23d1a806f1fddb5ce379730712347b267b7c7de4599b8ba70`; 1,836,646 bytes after decompression). The application build already carries this Flutter notice archive.
The inventory does not include dependency edges, a release-only Python environment, all native Windows/C++ components, a complete PDFium notice review, OCR model-weight files, or model weights. It does not decide whether any license permits a specific commercial distribution. Continue the manual source, hash, notice, and terms review in `LICENSE_REVIEW_2026-10.md` for the exact release artifacts.
## Regenerate
From the repository root, after installing Python requirements in `.venv` and resolving Flutter packages:
```powershell
& .\.venv\Scripts\python.exe .\scripts\generate_component_inventory.py
```
To hash the notices archive from a Windows build, add `--flutter-notices <path-to-NOTICES.Z>`. The script reads installed Python distribution metadata, the Flutter lock and package cache, and the passed notice archive; it does not install packages or inspect model weights.