30 lines
2.2 KiB
Markdown
30 lines
2.2 KiB
Markdown
# OpenCode task: build a conservative Flutter license evidence scan
|
|
|
|
## Goal
|
|
|
|
Create a repeatable, local-only screening report for the Flutter packages currently listed in `sbom/component-inventory.json`. The inventory already stores SHA-256 hashes for 104 Flutter license files, while 101 are deliberately left unclassified. Reduce manual triage by detecting likely standard license text without treating a text match as a legal conclusion.
|
|
|
|
## Read first
|
|
|
|
- `LICENSE_REVIEW_2026-10.md`
|
|
- `sbom/README.md`
|
|
- `sbom/component-inventory.json`
|
|
- `scripts/generate_component_inventory.py`
|
|
- `tests/test_component_inventory.py`
|
|
- `flutter_app/pubspec.lock` and `.dart_tool/package_config.json`
|
|
|
|
## Deliverables
|
|
|
|
1. Add a deterministic Python script that reads the existing inventory and the resolved Pub package cache, verifies each source license file against its recorded SHA-256, and emits one record per eligible package.
|
|
2. Detect only conservative license-text candidates (for example MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, and MPL-2.0). Include the literal matched evidence phrase, source filename/hash, package/version, and a status such as `candidate_requires_human_review`.
|
|
3. Mark composite, bundled, missing, modified, or ambiguous texts as `unclassified` rather than guessing. Never infer a package's legal grant from the license title alone, and never promote a candidate to an approved SPDX license in the current SBOM.
|
|
4. Add tests for supported candidates, ambiguous/composite text, unknown text, and hash mismatch. Use only temporary directories inside the test fixture root.
|
|
5. Add a generated screening artifact and explain its limits in `sbom/README.md`; update `ROADMAP.md` with counts and verification evidence. Do not mark commercial approval complete.
|
|
|
|
## Constraints
|
|
|
|
- Work only in this repository and keep the installed-package inventory unchanged unless its schema needs a documented, tested extension.
|
|
- Do not access the network, install packages, change user/global configuration, or inspect secrets.
|
|
- Do not edit model licenses, OCR weights, Groq terms, or native Windows/PDFium conclusions in this task.
|
|
- Do not commit or push. Report changed paths, checks run, candidate/unclassified counts, and any blocker.
|