{
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4774f2b0-0c20-4925-ae08-3f2374534893",
  "version": 1,
  "metadata": {
    "timestamp": "2026-01-01T00:00:00Z",
    "tools": {
      "components": [
        {
          "type": "application",
          "name": "novus-sbom-fixture",
          "version": "1.0.0"
        }
      ]
    },
    "authors": [
      {
        "name": "Orchard SBOM Team (fictional)",
        "email": "sbom@orchard.example"
      }
    ],
    "component": {
      "type": "container",
      "bom-ref": "pkg:oci/orchard-gateway@sha256%3Ad09edb133f6122a6ada56f6e62db4a1d0a2fa4faef6aa8948b1aad1c9b49eb76",
      "name": "registry.orchard.example/orchard/gateway",
      "version": "sha256:d09edb133f6122a6ada56f6e62db4a1d0a2fa4faef6aa8948b1aad1c9b49eb76",
      "purl": "pkg:oci/orchard-gateway@sha256%3Ad09edb133f6122a6ada56f6e62db4a1d0a2fa4faef6aa8948b1aad1c9b49eb76",
      "properties": [
        {
          "name": "novus:sample",
          "value": "SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented."
        }
      ]
    },
    "properties": [
      {
        "name": "novus:sample",
        "value": "SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented."
      }
    ]
  },
  "components": [
    {
      "type": "operating-system",
      "bom-ref": "os-sample",
      "name": "example-linux",
      "version": "3.20"
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/%40orchard-example/router@2.1.3",
      "name": "@orchard-example/router",
      "version": "2.1.3",
      "purl": "pkg:npm/%40orchard-example/router@2.1.3",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "d17f0a5171a018c41cdaaa2701b6c32bf49f7404032fa45e5721e2b794cd2e51"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/@orchard-example/router/-/router-2.1.3.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/router"
        }
      ]
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/%40orchard-example/http-core@1.8.0",
      "name": "@orchard-example/http-core",
      "version": "1.8.0",
      "purl": "pkg:npm/%40orchard-example/http-core@1.8.0",
      "licenses": [
        {
          "license": {
            "id": "MIT"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "05dc223ec1875dfd80d8c5873f8c29f036f98587f2fe2d02abc7c718bfb4b8bf"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/@orchard-example/http-core/-/http-core-1.8.0.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/http-core"
        }
      ]
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/example-metrics@4.0.0",
      "name": "example-metrics",
      "version": "4.0.0",
      "purl": "pkg:npm/example-metrics@4.0.0",
      "licenses": [
        {
          "license": {
            "id": "MIT"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "4a8930c617fd12bb99d26e868224d9918e4a3e00f8dd26b876ed19eb6e664f73"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/example-metrics/-/example-metrics-4.0.0.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/example-metrics"
        }
      ]
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/example-cache@0.9.2",
      "name": "example-cache",
      "version": "0.9.2",
      "purl": "pkg:npm/example-cache@0.9.2",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "f7af2ad2d3c3daaa5991b0eae38ffa151a2e2f3bf0f2bdd7333adc3a1dc860f7"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/example-cache/-/example-cache-0.9.2.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/example-cache"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:oci/orchard-gateway@sha256%3Ad09edb133f6122a6ada56f6e62db4a1d0a2fa4faef6aa8948b1aad1c9b49eb76",
      "dependsOn": [
        "os-sample",
        "pkg:npm/%40orchard-example/router@2.1.3",
        "pkg:npm/%40orchard-example/http-core@1.8.0",
        "pkg:npm/example-metrics@4.0.0",
        "pkg:npm/example-cache@0.9.2"
      ]
    }
  ]
}
