Files
sovereign_ai/SovereignAI-Starter/OPEN_CODE_TASK_LICENSE_EVIDENCE.md
T

2.2 KiB

OpenCode task: build a conservative Flutter license evidence scan

Goal

Create a repeatable, local-only screening report for the Flutter packages currently listed in sbom/component-inventory.json. The inventory already stores SHA-256 hashes for 104 Flutter license files, while 101 are deliberately left unclassified. Reduce manual triage by detecting likely standard license text without treating a text match as a legal conclusion.

Read first

  • LICENSE_REVIEW_2026-10.md
  • sbom/README.md
  • sbom/component-inventory.json
  • scripts/generate_component_inventory.py
  • tests/test_component_inventory.py
  • flutter_app/pubspec.lock and .dart_tool/package_config.json

Deliverables

  1. Add a deterministic Python script that reads the existing inventory and the resolved Pub package cache, verifies each source license file against its recorded SHA-256, and emits one record per eligible package.
  2. Detect only conservative license-text candidates (for example MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, and MPL-2.0). Include the literal matched evidence phrase, source filename/hash, package/version, and a status such as candidate_requires_human_review.
  3. Mark composite, bundled, missing, modified, or ambiguous texts as unclassified rather than guessing. Never infer a package's legal grant from the license title alone, and never promote a candidate to an approved SPDX license in the current SBOM.
  4. Add tests for supported candidates, ambiguous/composite text, unknown text, and hash mismatch. Use only temporary directories inside the test fixture root.
  5. Add a generated screening artifact and explain its limits in sbom/README.md; update ROADMAP.md with counts and verification evidence. Do not mark commercial approval complete.

Constraints

  • Work only in this repository and keep the installed-package inventory unchanged unless its schema needs a documented, tested extension.
  • Do not access the network, install packages, change user/global configuration, or inspect secrets.
  • Do not edit model licenses, OCR weights, Groq terms, or native Windows/PDFium conclusions in this task.
  • Do not commit or push. Report changed paths, checks run, candidate/unclassified counts, and any blocker.