Flutter with DevFlow: scanning, verification, isolation

DevFlow runs Flutter tasks in devflow/flutter:stable and caps every test container at 4 CPUs and 4 GB of memory; there is no dependency audit for its packages yet.

Manifests
pubspec.yaml
Dependency scanner
None yet
Agent image
devflow/flutter:stable
Scan timeout
Not applicable
Container caps
4 CPUs, 4 GB memory (6 GB with swap), 512 processes

How a Flutter task runs

You describe the task, the planner reads the code and may ask questions, and implementation starts only after you approve the plan. The plan splits into at most 8 subtasks, implemented in a git worktree on the branch devflow/<id>, then verified, summarized and opened as a PR. Agents work in the image listed above.

Dependency scanning

There is no dependency audit for this ecosystem yet: none of DevFlow's scanners reads pubspec.yaml. Known-vulnerable packages are not flagged, so keep your own audit in CI until one exists.

Verification gates

Gates run only the configured test_commands, stored as bare in-container commands, for example dart analyze and flutter test. A repo that pins an SDK release in .fvmrc or .flutter-version runs on the image built for that version, and falls back to :stable with a warning when that build is missing. With no commands configured, the task can merge unverified, and the timeline shows it.

Isolation and limits

The SDK in the image is opened to any user ID, because the stock cirruslabs SDK is root-owned and fails under the container's --user. Test and build commands run in Docker as a non-root user, capped by default at 4 GB of memory (6 GB with swap), 4 CPUs and 512 processes. The agent can write only to the task worktree and its git data, toolchain paths such as /usr stay read-only, and code-writing roles reach only allowlisted hosts.

A typical task

Fix a widget test after a layout change. The planner reads the widget and its test, then proposes a plan you approve. The implementer updates both in the worktree, the gate runs the widget tests in the pinned SDK image, and the PR opens on a devflow branch.

FAQ

Are pub dependencies audited?

No. DevFlow has no dependency scanner for Dart or pub packages yet, so nothing checks pubspec.lock for known vulnerabilities.

What if the pinned SDK is too old for a dependency?

Pub's version solving failure is classed as a build environment error, not a code defect, so the task is not sent back for rework.

Does the image include Node or Python?

No. It has the SDK, Dart and git, and no Node, Go, Python, Java or .NET beyond what the SDK bundles.