2.5 KiB
Preliminary component inventory
component-inventory.json is a point-in-time CycloneDX 1.5 inventory assembled from the active Python virtual environment, flutter_app/pubspec.lock, and (when supplied) the bundled Flutter NOTICES.Z file. It is an engineering aid, not a complete or legally approved commercial SBOM.
The generator performs local JSON and uniqueness checks; this snapshot has not yet been validated against the official CycloneDX 1.5 JSON schema. The pub PURL type is listed by the Package-URL type registry.
Snapshot captured on 2026-10-04
- 50 Python distributions from
.venv: 8 direct runtime requirements, 1 optional OCR requirement, and 41 installed transitive/development packages. Python versions are the versions installed in this local environment;requirements.txtstill uses ranges and is not a fully pinned production lock. - 104 Flutter pub packages from the resolved lock: 15 direct main, 3 direct development, and 86 transitive/SDK packages.
- 104 package license files have SHA-256 evidence. For 101 components the inventory can find a license file but deliberately does not classify its legal terms automatically. The remaining declarations come from distribution/package metadata or the Flutter SDK license notice.
- The Windows Debug artifact bundled
NOTICES.Z(SHA-256eb0096c70ca8a2b23d1a806f1fddb5ce379730712347b267b7c7de4599b8ba70; 1,836,646 bytes after decompression). The application build already carries this Flutter notice archive.
The inventory does not include dependency edges, a release-only Python environment, all native Windows/C++ components, a complete PDFium notice review, OCR model-weight files, or model weights. It does not decide whether any license permits a specific commercial distribution. Continue the manual source, hash, notice, and terms review in LICENSE_REVIEW_2026-10.md for the exact release artifacts.
Regenerate
From the repository root, after installing Python requirements in .venv and resolving Flutter packages:
& .\.venv\Scripts\python.exe .\scripts\generate_component_inventory.py
To hash the notices archive from a Windows build, add --flutter-notices <path-to-NOTICES.Z>. The script reads installed Python distribution metadata, the Flutter lock and package cache, and the passed notice archive; it does not install packages or inspect model weights.