Preliminary component inventory
component-inventory.json is a point-in-time CycloneDX 1.5 inventory assembled from the active Python virtual environment, flutter_app/pubspec.lock, the installed PDFium native binary and its wheel-bundled build notices, observed local EasyOCR model weights, and (when supplied) the bundled Flutter NOTICES.Z file. Host-local runtime files are observations for the current machine, not a release artifact manifest. This is an engineering aid, not a complete or legally approved commercial SBOM.
The generator performs local JSON and uniqueness checks; this snapshot has not yet been validated against the official CycloneDX 1.5 JSON schema. The pub PURL type is listed by the Package-URL type registry.
Snapshot captured on 2026-10-07
- 50 Python distributions from
.venv: 8 direct runtime requirements, 1 optional OCR requirement, and 41 installed transitive/development packages. Python versions are the versions installed in this local environment;requirements.txtstill uses ranges and is not a fully pinned production lock. - 104 Flutter pub packages from the resolved lock: 15 direct main, 3 direct development, and 86 transitive/SDK packages.
- 104 package license files have SHA-256 evidence. For 101 components the inventory can find a license file but deliberately does not classify its legal terms automatically. The remaining declarations come from distribution/package metadata or the Flutter SDK license notice.
- A separate text-signature triage report is generated at
flutter-license-triage.json. At this snapshot it found 102 package license files directly in resolved package roots: 99 have a single recognizable candidate signature (78 BSD-3-Clause, 16 MIT, 3 Apache-2.0, 1 BSD-2-Clause, and 1 MPL-2.0); 3 files are composite notices with multiple signatures, includingfile_selector_android,url_launcher_web, and the Fluttersky_enginebundle. Two SDK packages have no package-root license file. The report also lists detected signatures in composite files without assigning them to a specific bundled component. These are candidates only, not legal classifications. Every item still needs a reviewer to confirm the package's declared terms, source and included notices; the counts do not replace the 104-file hash evidence in the main inventory. - The Windows Debug artifact bundled
NOTICES.Z(SHA-256eb0096c70ca8a2b23d1a806f1fddb5ce379730712347b267b7c7de4599b8ba70; 1,836,646 bytes after decompression). The application build already carries this Flutter notice archive. - Three host-local runtime artifacts are now hashed as CycloneDX file/model components.
pypdfium25.13.0'spdfium.dllis 7,260,672 bytes (SHA-256fb898a1f5ace57805834f390407500bdb6ef93eff326a252ad334a8aae809d8e); the inventory records hashes for 16 Windows x64BUILD_LICENSESfiles shipped in the wheel. - EasyOCR 1.7.2's local
arabic.pth(215,400,714 bytes; SHA-2562a9afd42c374deb98aed0b53c9b77d75e1d00d4e0501f3b0276c54190c89b1a8) andcraft_mlt_25k.pth(83,152,330 bytes; SHA-2564a5efbfb48b4081100544e75e1e2b57f8de3d84f213004b14b85fd4b3748db17) match the MD5 identifiers in the pinned EasyOCR model configuration. This confirms artifact identity against that manifest, not redistribution rights; both model components remain marked for human license review.english_g2.pth, which the current Arabic/English reader expects, is absent from this host's OCR model directory and is recorded as missing. The OCR code may download it when first initializing because downloads are enabled by default.
The inventory does not include dependency edges, a release-only Python environment, all native Windows/C++ components, or completed classification of PDFium/OCR notices. It does not decide whether any license permits a specific commercial distribution. Continue the manual source, hash, notice, and terms review in LICENSE_REVIEW_2026-10.md for the exact release artifacts.
The Flutter candidate report can be regenerated from the repository root with:
& .\.venv\Scripts\python.exe .\scripts\generate_flutter_license_triage.py
It uses only local lockfile/package-cache files and SHA-256 hashes. A missing or ambiguous entry must remain unresolved until reviewed against its package and upstream terms.
Regenerate
From the repository root, after installing Python requirements in .venv and resolving Flutter packages:
& .\.venv\Scripts\python.exe .\scripts\generate_component_inventory.py
To hash the notices archive from a Windows build, add --flutter-notices <path-to-NOTICES.Z>. The script reads installed Python distribution metadata, the Flutter lock and package cache, the installed pypdfium2_raw binary and its license notices, the three EasyOCR model files from LOCAL_OCR_MODEL_DIR (or the app's default model directory), and the passed Flutter notice archive. It does not install packages, download models, or infer that a detected file is legally redistributable.