core/utils/dependency_sbom library
Pure, no-Flutter-dependency dependency-security/SBOM (Software Bill of
Materials) support — parses pubspec.lock, classifies each
dependency's bundled LICENSE file text, and cross-checks the result
against an optional vulnerability-advisory list and a suppression
baseline. tool/dependency_sbom_check.dart wires this into a
genuinely headless dart run CI check.
What this does NOT do: scan for real CVEs. There is no bundled
vulnerability database and no network call here — auditDependencies
only cross-checks DependencyEntry against whatever
VulnerabilityAdvisory list the CALLER supplies (exported from
osv-scanner, GitHub Dependabot, or a manually curated list). Calling
this a "vulnerability scanner" would overstate what it is: a GATE that
enforces a policy over data someone else produced.
Classes
- DependencyEntry
-
One resolved package from
pubspec.lock. - SbomDocument
-
A reproducible bill-of-materials document —
toJson()'sentrieslist is always in the same (name-sorted) order parsePubspecLock already guarantees, so hashing/diffing 2 SBOMs of the same lock file is meaningful. - SbomIssue
- SbomSuppression
-
A pre-approved exception — owner and
expiresAtMsAfterEpochare both required (not optional) because an unowned or permanent suppression is exactly the "false positive with no accountability and no forced re-review" this task's acceptance criteria calls out. OnceexpiresAtMsAfterEpochhas passed (checked against auditDependencies's ownnowMs), the suppression simply stops applying — no special "expired" state to handle, the issue just reappears in the next audit. - VulnerabilityAdvisory
- One vulnerability advisory — supplied by the CALLER (see this file's doc comment), never produced by this file itself.
Enums
- AdvisorySeverity
- DependencySource
- DependencyType
- LicenseCategory
-
A
LICENSEfile's text, reduced to one of 3 buckets — deliberately coarse (not "is this exact SPDX id compatible with our own license"): this is a policy GATE flagging "needs a human to look," not a legal compatibility engine. - SbomIssueKind
Functions
-
auditDependencies(
{required List< DependencyEntry> entries, required Map<String, LicenseCategory> licenseByPackage, required int nowMs, List<VulnerabilityAdvisory> advisories = const [], List<SbomSuppression> suppressions = const [], Set<String> unpinnedPackages = const {}}) → List<SbomIssue> -
Cross-checks
entriesagainst license classifications, an optionaladvisorieslist, andpinnedOnlypolicy, returning every issue not covered by an unexpired SbomSuppression. -
classifyLicenseText(
String? licenseFileContent) → LicenseCategory -
Classifies a
LICENSEfile's raw text by matching well-known license header text — case-sensitive on purpose (a license file's own actual wording is what a legal reviewer would look at too, a lowercase substring match risks matching unrelated prose). -
parsePubspecLock(
String content) → List< DependencyEntry> -
Parses a
pubspec.lockfile's content into every resolved package, sorted by name — this ordering is what makes the resulting SbomDocument reproducible: the same lock file always produces byte-identical JSON, regardless of the lock file's own key order or anyMapiteration order.