{
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a1c48e8a-34d0-4c12-a669-7dbee225dcd6",
  "version": 1,
  "metadata": {
    "timestamp": "2026-01-01T00:00:00Z",
    "tools": {
      "components": [
        {
          "type": "application",
          "name": "novus-sbom-fixture",
          "version": "1.0.0"
        }
      ]
    },
    "authors": [
      {
        "name": "Orchard SBOM Team (fictional)",
        "email": "sbom@orchard.example"
      }
    ],
    "component": {
      "type": "application",
      "bom-ref": "pkg:npm/%40orchard-example/gateway@4.2.0",
      "name": "@orchard-example/gateway",
      "version": "4.2.0",
      "purl": "pkg:npm/%40orchard-example/gateway@4.2.0",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "cde01f0c8ff9d62ef958a3de288a2f1084db14bd47e1e10ff39a52412cca613f"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/@orchard-example/gateway/-/gateway-4.2.0.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/gateway"
        }
      ]
    },
    "properties": [
      {
        "name": "novus:sample",
        "value": "SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented."
      }
    ]
  },
  "components": [
    {
      "type": "library",
      "bom-ref": "pkg:npm/%40orchard-example/router@2.1.3",
      "name": "@orchard-example/router",
      "version": "2.1.3",
      "purl": "pkg:npm/%40orchard-example/router@2.1.3",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "d17f0a5171a018c41cdaaa2701b6c32bf49f7404032fa45e5721e2b794cd2e51"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/@orchard-example/router/-/router-2.1.3.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/router"
        }
      ]
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/%40orchard-example/http-core@1.8.0",
      "name": "@orchard-example/http-core",
      "version": "1.8.0",
      "purl": "pkg:npm/%40orchard-example/http-core@1.8.0",
      "licenses": [
        {
          "license": {
            "id": "MIT"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "05dc223ec1875dfd80d8c5873f8c29f036f98587f2fe2d02abc7c718bfb4b8bf"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/@orchard-example/http-core/-/http-core-1.8.0.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/http-core"
        }
      ]
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/example-metrics@4.0.0",
      "name": "example-metrics",
      "version": "4.0.0",
      "purl": "pkg:npm/example-metrics@4.0.0",
      "licenses": [
        {
          "license": {
            "id": "MIT"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "4a8930c617fd12bb99d26e868224d9918e4a3e00f8dd26b876ed19eb6e664f73"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/example-metrics/-/example-metrics-4.0.0.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/example-metrics"
        }
      ]
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/example-cache@0.9.2",
      "name": "example-cache",
      "version": "0.9.2",
      "purl": "pkg:npm/example-cache@0.9.2",
      "licenses": [
        {
          "license": {
            "id": "BSD-3-Clause"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "f7af2ad2d3c3daaa5991b0eae38ffa151a2e2f3bf0f2bdd7333adc3a1dc860f7"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/example-cache/-/example-cache-0.9.2.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/example-cache"
        }
      ]
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/example-crypto-shim@1.2.0",
      "name": "example-crypto-shim",
      "version": "1.2.0",
      "purl": "pkg:npm/example-crypto-shim@1.2.0",
      "licenses": [
        {
          "license": {
            "id": "MIT"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "25b4571f3faedb8df3979d9e509e331b6b88503d8d0057e6414e936e084a56cb"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/example-crypto-shim/-/example-crypto-shim-1.2.0.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/example-crypto-shim"
        }
      ]
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/example-logger@3.4.1",
      "name": "example-logger",
      "version": "3.4.1",
      "purl": "pkg:npm/example-logger@3.4.1",
      "licenses": [
        {
          "license": {
            "id": "MIT"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "7fb72ea58987e5327259b66384f96f5e657c3ce5225b8891c567cac6b58430ec"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/example-logger/-/example-logger-3.4.1.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/example-logger"
        }
      ]
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/example-retry@1.0.4",
      "name": "example-retry",
      "version": "1.0.4",
      "purl": "pkg:npm/example-retry@1.0.4",
      "licenses": [
        {
          "license": {
            "id": "ISC"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "4f2a78f8fb4883a2efd6b73b447f632599790c08e25bb7184f501b5f2b9af33f"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/example-retry/-/example-retry-1.0.4.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/example-retry"
        }
      ]
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/example-json-path@2.0.5",
      "name": "example-json-path",
      "version": "2.0.5",
      "purl": "pkg:npm/example-json-path@2.0.5",
      "licenses": [
        {
          "license": {
            "id": "MIT"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "74e30e4812a0cc92bd7c1a965e6f953f5d92b9eaf3cd77d90663a7344e939b63"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/example-json-path/-/example-json-path-2.0.5.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/example-json-path"
        }
      ]
    },
    {
      "type": "library",
      "bom-ref": "pkg:npm/example-yaml-lite@1.1.7",
      "name": "example-yaml-lite",
      "version": "1.1.7",
      "purl": "pkg:npm/example-yaml-lite@1.1.7",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "d7094de3c8e15621381e5f9f02c0eecb9977d249a8a06ab2b0a34f5344a039af"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/example-yaml-lite/-/example-yaml-lite-1.1.7.tgz"
        },
        {
          "type": "vcs",
          "url": "https://git.orchard.example/example-yaml-lite"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40orchard-example/gateway@4.2.0",
      "dependsOn": [
        "pkg:npm/%40orchard-example/router@2.1.3",
        "pkg:npm/%40orchard-example/http-core@1.8.0",
        "pkg:npm/example-metrics@4.0.0",
        "pkg:npm/example-cache@0.9.2",
        "pkg:npm/example-crypto-shim@1.2.0"
      ]
    },
    {
      "ref": "pkg:npm/%40orchard-example/router@2.1.3",
      "dependsOn": [
        "pkg:npm/example-logger@3.4.1",
        "pkg:npm/example-retry@1.0.4"
      ]
    },
    {
      "ref": "pkg:npm/%40orchard-example/http-core@1.8.0",
      "dependsOn": [
        "pkg:npm/example-logger@3.4.1",
        "pkg:npm/example-json-path@2.0.5"
      ]
    },
    {
      "ref": "pkg:npm/example-metrics@4.0.0",
      "dependsOn": [
        "pkg:npm/example-logger@3.4.1"
      ]
    },
    {
      "ref": "pkg:npm/example-cache@0.9.2",
      "dependsOn": [
        "pkg:npm/example-yaml-lite@1.1.7"
      ]
    },
    {
      "ref": "pkg:npm/example-crypto-shim@1.2.0",
      "dependsOn": []
    },
    {
      "ref": "pkg:npm/example-logger@3.4.1",
      "dependsOn": []
    },
    {
      "ref": "pkg:npm/example-retry@1.0.4",
      "dependsOn": []
    },
    {
      "ref": "pkg:npm/example-json-path@2.0.5",
      "dependsOn": []
    },
    {
      "ref": "pkg:npm/example-yaml-lite@1.1.7",
      "dependsOn": [
        "pkg:npm/example-json-path@2.0.5"
      ]
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "vuln-novus-sample-2026-0001",
      "id": "NOVUS-SAMPLE-2026-0001",
      "source": {
        "name": "NOVUS-SAMPLE",
        "url": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0001"
      },
      "references": [
        {
          "id": "SAMPLE-CVE-2026-0001",
          "source": {
            "name": "SAMPLE-ALIAS"
          }
        }
      ],
      "ratings": [
        {
          "source": {
            "name": "NOVUS-SAMPLE"
          },
          "score": 8.1,
          "severity": "high",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        }
      ],
      "cwes": [
        20
      ],
      "description": "SAMPLE advisory: fabricated improper-input-validation issue in a fictional logging library.",
      "recommendation": "Upgrade example-logger to 3.5.0 (fictional fixed version).",
      "published": "2026-01-05T00:00:00Z",
      "updated": "2026-01-10T00:00:00Z",
      "affects": [
        {
          "ref": "pkg:npm/example-logger@3.4.1",
          "versions": [
            {
              "range": "<3.5.0",
              "status": "affected"
            }
          ]
        }
      ]
    },
    {
      "bom-ref": "vuln-novus-sample-2026-0002",
      "id": "NOVUS-SAMPLE-2026-0002",
      "source": {
        "name": "NOVUS-SAMPLE",
        "url": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0002"
      },
      "references": [
        {
          "id": "SAMPLE-CVE-2026-0002",
          "source": {
            "name": "SAMPLE-ALIAS"
          }
        }
      ],
      "ratings": [
        {
          "source": {
            "name": "NOVUS-SAMPLE"
          },
          "score": 9.3,
          "severity": "critical",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        }
      ],
      "cwes": [
        502
      ],
      "description": "SAMPLE advisory: fabricated unsafe-deserialisation issue in a fictional cache library.",
      "recommendation": "Upgrade example-cache to 0.9.5 (fictional fixed version).",
      "published": "2026-01-05T00:00:00Z",
      "updated": "2026-01-10T00:00:00Z",
      "affects": [
        {
          "ref": "pkg:npm/example-cache@0.9.2",
          "versions": [
            {
              "range": ">=0.9.0 <0.9.5",
              "status": "affected"
            }
          ]
        }
      ]
    },
    {
      "bom-ref": "vuln-novus-sample-2026-0003",
      "id": "NOVUS-SAMPLE-2026-0003",
      "source": {
        "name": "NOVUS-SAMPLE",
        "url": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0003"
      },
      "references": [
        {
          "id": "SAMPLE-CVE-2026-0003",
          "source": {
            "name": "SAMPLE-ALIAS"
          }
        }
      ],
      "ratings": [
        {
          "source": {
            "name": "NOVUS-SAMPLE"
          },
          "score": 5.4,
          "severity": "medium",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
        }
      ],
      "cwes": [
        400
      ],
      "description": "SAMPLE advisory: fabricated uncontrolled-resource-consumption issue in a fictional parser.",
      "recommendation": "Upgrade example-yaml-lite to 1.2.0 (fictional fixed version).",
      "published": "2026-01-05T00:00:00Z",
      "updated": "2026-01-10T00:00:00Z",
      "affects": [
        {
          "ref": "pkg:npm/example-yaml-lite@1.1.7",
          "versions": [
            {
              "range": "<1.2.0",
              "status": "affected"
            }
          ]
        }
      ]
    },
    {
      "bom-ref": "vuln-novus-sample-2026-0004",
      "id": "NOVUS-SAMPLE-2026-0004",
      "source": {
        "name": "NOVUS-SAMPLE",
        "url": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0004"
      },
      "references": [
        {
          "id": "SAMPLE-CVE-2026-0004",
          "source": {
            "name": "SAMPLE-ALIAS"
          }
        }
      ],
      "ratings": [
        {
          "source": {
            "name": "NOVUS-SAMPLE"
          },
          "score": 3.1,
          "severity": "low",
          "method": "CVSSv31",
          "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L"
        }
      ],
      "cwes": [
        770
      ],
      "description": "SAMPLE advisory: fabricated allocation-without-limits issue in a fictional query library.",
      "recommendation": "Upgrade example-json-path to 2.1.0 (fictional fixed version).",
      "published": "2026-01-05T00:00:00Z",
      "updated": "2026-01-10T00:00:00Z",
      "affects": [
        {
          "ref": "pkg:npm/example-json-path@2.0.5",
          "versions": [
            {
              "range": "<2.1.0",
              "status": "affected"
            }
          ]
        }
      ]
    }
  ]
}
