Files
sovereign_ai/SovereignAI-Starter/OPEN_CODE_TASK_LICENSE_EVIDENCE.md
T

30 lines
2.2 KiB
Markdown

# OpenCode task: build a conservative Flutter license evidence scan
## Goal
Create a repeatable, local-only screening report for the Flutter packages currently listed in `sbom/component-inventory.json`. The inventory already stores SHA-256 hashes for 104 Flutter license files, while 101 are deliberately left unclassified. Reduce manual triage by detecting likely standard license text without treating a text match as a legal conclusion.
## Read first
- `LICENSE_REVIEW_2026-10.md`
- `sbom/README.md`
- `sbom/component-inventory.json`
- `scripts/generate_component_inventory.py`
- `tests/test_component_inventory.py`
- `flutter_app/pubspec.lock` and `.dart_tool/package_config.json`
## Deliverables
1. Add a deterministic Python script that reads the existing inventory and the resolved Pub package cache, verifies each source license file against its recorded SHA-256, and emits one record per eligible package.
2. Detect only conservative license-text candidates (for example MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, and MPL-2.0). Include the literal matched evidence phrase, source filename/hash, package/version, and a status such as `candidate_requires_human_review`.
3. Mark composite, bundled, missing, modified, or ambiguous texts as `unclassified` rather than guessing. Never infer a package's legal grant from the license title alone, and never promote a candidate to an approved SPDX license in the current SBOM.
4. Add tests for supported candidates, ambiguous/composite text, unknown text, and hash mismatch. Use only temporary directories inside the test fixture root.
5. Add a generated screening artifact and explain its limits in `sbom/README.md`; update `ROADMAP.md` with counts and verification evidence. Do not mark commercial approval complete.
## Constraints
- Work only in this repository and keep the installed-package inventory unchanged unless its schema needs a documented, tested extension.
- Do not access the network, install packages, change user/global configuration, or inspect secrets.
- Do not edit model licenses, OCR weights, Groq terms, or native Windows/PDFium conclusions in this task.
- Do not commit or push. Report changed paths, checks run, candidate/unclassified counts, and any blocker.