# Sec Dependency And Supply Chain Report V0.9.2.2.1 **Document type:** Security / Dependency and Supply Chain Report **Version:** 0.9.2 **Status:** Baseline Candidate **Language:** English **Product:** Chanora **Repo path:** `docs/security/dependency-and-supply-chain-report.md` --- ## 1. Purpose This report records Chanora dependency inventory, license review, vulnerability review, SBOM status, and supply-chain release readiness. ## 2. Dependency Scope | Ecosystem | In scope | |---|---| | Flutter / Dart | `pubspec.yaml`, transitive packages, Flutter SDK version | | Rust | `Cargo.toml`, `Cargo.lock`, crates, features | | Protocol library | `tsclientlib` and related crates/dependencies | | Native audio | Platform audio libraries, native build dependencies, bindings | | Build tooling | CI actions, build scripts, code generators | | Packaging | Platform packaging tools and signing tools | ## 3. Required Outputs | Output | Required before external release | |---|---| | Dependency inventory | Yes | | License report | Yes | | Vulnerability scan report | Yes | | SBOM | Yes | | Critical/high vulnerability disposition | Yes | | Unknown license disposition | Yes | | Build provenance record | Yes | | Artifact hash record | Yes | ## 4. Dependency Inventory | Component | Ecosystem | Version | License | Source | Risk | Notes | |---|---|---|---|---|---|---| | Flutter SDK | Flutter | TBD | TBD | TBD | TBD | TBD | | Dart packages | Dart | TBD | TBD | TBD | TBD | TBD | | Rust toolchain | Rust | TBD | TBD | TBD | TBD | TBD | | Rust crates | Rust | TBD | TBD | TBD | TBD | TBD | | `tsclientlib` | Rust/protocol | TBD | TBD | TBD | TBD | TBD | | Native audio dependencies | Native | TBD | TBD | TBD | TBD | TBD | | CI actions/tools | Build | TBD | TBD | TBD | TBD | TBD | ## 5. License Review | License category | Policy | |---|---| | Permissive licenses | Generally acceptable after review | | Copyleft licenses | Requires legal review before release | | Unknown licenses | Release blocker until resolved | | Proprietary dependencies | Requires explicit approval | | Incompatible licenses | Release blocker unless removed or legal waiver approved | ## 6. Vulnerability Review | Finding ID | Dependency | Severity | CVE / advisory | Status | Disposition | |---|---|---|---|---|---| | TBD | TBD | TBD | TBD | TBD | TBD | ## 7. SBOM | Field | Value | |---|---| | SBOM format | TBD: SPDX / CycloneDX / other | | SBOM tool | TBD | | SBOM file | TBD | | SBOM generation date | TBD | | SBOM reviewer | TBD | ## 8. Build Provenance | Field | Value | |---|---| | Git commit SHA | TBD | | Git tag | TBD | | CI pipeline ID | TBD | | Build environment | TBD | | Artifact hashes | TBD | | Signing identity | TBD | | Reproducibility status | TBD | ## 9. Release Gate | Gate | Required result | |---|---| | Critical vulnerabilities | None open without approved waiver | | High vulnerabilities | None open without approved waiver | | Unknown licenses | None open without approved waiver | | SBOM | Generated and archived | | License report | Reviewed | | Dependency report | Approved | ## 10. Approval | Role | Name | Decision | Date | |---|---|---|---| | Security Reviewer | TBD | Pending | TBD | | Legal Reviewer | TBD | Pending | TBD | | Engineering Owner | TBD | Pending | TBD | | Release Manager | TBD | Pending | TBD | ## 11. Change History | Version | Date | Description | |---|---|---| | 0.9.0 | 2026-05-14 | Initial dependency and supply-chain report template. | ## Baseline Candidate 0.9.1 Update | Version | Date | Description | |---|---|---| | 0.9.1 | 2026-05-14 | Updated baseline after product decision closure: Apple App Store SDK gate uses Xcode 26+ and iOS 26 / iPadOS 26 SDK+ since 2026-04-28, platform baselines and decision traceability propagated across the document set. | ## Baseline Candidate 0.9.2 Update | Version | Date | Description | |---|---|---| | 0.9.2 | 2026-05-14 | Corrected Apple App Store Connect upload gate to 2026-04-28 and checked full-package naming, references, and coverage. |