core/utils/dependency_sbom library

Pure, no-Flutter-dependency dependency-security/SBOM (Software Bill of Materials) support — parses pubspec.lock, classifies each dependency's bundled LICENSE file text, and cross-checks the result against an optional vulnerability-advisory list and a suppression baseline. tool/dependency_sbom_check.dart wires this into a genuinely headless dart run CI check.

What this does NOT do: scan for real CVEs. There is no bundled vulnerability database and no network call here — auditDependencies only cross-checks DependencyEntry against whatever VulnerabilityAdvisory list the CALLER supplies (exported from osv-scanner, GitHub Dependabot, or a manually curated list). Calling this a "vulnerability scanner" would overstate what it is: a GATE that enforces a policy over data someone else produced.

Classes

DependencyEntry
One resolved package from pubspec.lock.
SbomDocument
A reproducible bill-of-materials document — toJson()'s entries list is always in the same (name-sorted) order parsePubspecLock already guarantees, so hashing/diffing 2 SBOMs of the same lock file is meaningful.
SbomIssue
SbomSuppression
A pre-approved exception — owner and expiresAtMsAfterEpoch are both required (not optional) because an unowned or permanent suppression is exactly the "false positive with no accountability and no forced re-review" this task's acceptance criteria calls out. Once expiresAtMsAfterEpoch has passed (checked against auditDependencies's own nowMs), the suppression simply stops applying — no special "expired" state to handle, the issue just reappears in the next audit.
VulnerabilityAdvisory
One vulnerability advisory — supplied by the CALLER (see this file's doc comment), never produced by this file itself.

Enums

AdvisorySeverity
DependencySource
DependencyType
LicenseCategory
A LICENSE file's text, reduced to one of 3 buckets — deliberately coarse (not "is this exact SPDX id compatible with our own license"): this is a policy GATE flagging "needs a human to look," not a legal compatibility engine.
SbomIssueKind

Functions

auditDependencies({required List<DependencyEntry> entries, required Map<String, LicenseCategory> licenseByPackage, required int nowMs, List<VulnerabilityAdvisory> advisories = const [], List<SbomSuppression> suppressions = const [], Set<String> unpinnedPackages = const {}}) → List<SbomIssue>
Cross-checks entries against license classifications, an optional advisories list, and pinnedOnly policy, returning every issue not covered by an unexpired SbomSuppression.
classifyLicenseText(String? licenseFileContent) → LicenseCategory
Classifies a LICENSE file's raw text by matching well-known license header text — case-sensitive on purpose (a license file's own actual wording is what a legal reviewer would look at too, a lowercase substring match risks matching unrelated prose).
parsePubspecLock(String content) → List<DependencyEntry>
Parses a pubspec.lock file's content into every resolved package, sorted by name — this ordering is what makes the resulting SbomDocument reproducible: the same lock file always produces byte-identical JSON, regardless of the lock file's own key order or any Map iteration order.