2.2 KiB
2.2 KiB
OpenCode task: build a conservative Flutter license evidence scan
Goal
Create a repeatable, local-only screening report for the Flutter packages currently listed in sbom/component-inventory.json. The inventory already stores SHA-256 hashes for 104 Flutter license files, while 101 are deliberately left unclassified. Reduce manual triage by detecting likely standard license text without treating a text match as a legal conclusion.
Read first
LICENSE_REVIEW_2026-10.mdsbom/README.mdsbom/component-inventory.jsonscripts/generate_component_inventory.pytests/test_component_inventory.pyflutter_app/pubspec.lockand.dart_tool/package_config.json
Deliverables
- Add a deterministic Python script that reads the existing inventory and the resolved Pub package cache, verifies each source license file against its recorded SHA-256, and emits one record per eligible package.
- Detect only conservative license-text candidates (for example MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, and MPL-2.0). Include the literal matched evidence phrase, source filename/hash, package/version, and a status such as
candidate_requires_human_review. - Mark composite, bundled, missing, modified, or ambiguous texts as
unclassifiedrather than guessing. Never infer a package's legal grant from the license title alone, and never promote a candidate to an approved SPDX license in the current SBOM. - Add tests for supported candidates, ambiguous/composite text, unknown text, and hash mismatch. Use only temporary directories inside the test fixture root.
- Add a generated screening artifact and explain its limits in
sbom/README.md; updateROADMAP.mdwith counts and verification evidence. Do not mark commercial approval complete.
Constraints
- Work only in this repository and keep the installed-package inventory unchanged unless its schema needs a documented, tested extension.
- Do not access the network, install packages, change user/global configuration, or inspect secrets.
- Do not edit model licenses, OCR weights, Groq terms, or native Windows/PDFium conclusions in this task.
- Do not commit or push. Report changed paths, checks run, candidate/unclassified counts, and any blocker.