##### SPDX tag-value document — SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented.

SPDXVersion: SPDX-2.3
DataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT
DocumentName: orchard-gateway-4.2.0
DocumentNamespace: https://sbom.orchard.example/spdx/6f442f00-f303-45a1-ada4-3935dd1206f0
Creator: Organization: Example Softworks (fictional)
Creator: Tool: novus-sbom-fixture-1.0.0
Created: 2026-01-01T00:00:00Z
CreatorComment: <text>Fictional component tree. No package named here exists.</text>

##### Package: @orchard-example/gateway

PackageName: @orchard-example/gateway
SPDXID: SPDXRef-Package-orchard-example-gateway
PackageVersion: 4.2.0
PackageSupplier: Organization: Example Softworks (fictional)
PackageDownloadLocation: https://registry.orchard.example/@orchard-example/gateway/-/gateway-4.2.0.tgz
FilesAnalyzed: false
PackageChecksum: SHA256: cde01f0c8ff9d62ef958a3de288a2f1084db14bd47e1e10ff39a52412cca613f
PackageLicenseConcluded: Apache-2.0
PackageLicenseDeclared: Apache-2.0
PackageCopyrightText: NOASSERTION
ExternalRef: PACKAGE-MANAGER purl pkg:npm/%40orchard-example/gateway@4.2.0

##### Package: @orchard-example/router

PackageName: @orchard-example/router
SPDXID: SPDXRef-Package-orchard-example-router
PackageVersion: 2.1.3
PackageSupplier: Organization: Example Softworks (fictional)
PackageDownloadLocation: https://registry.orchard.example/@orchard-example/router/-/router-2.1.3.tgz
FilesAnalyzed: false
PackageChecksum: SHA256: d17f0a5171a018c41cdaaa2701b6c32bf49f7404032fa45e5721e2b794cd2e51
PackageLicenseConcluded: Apache-2.0
PackageLicenseDeclared: Apache-2.0
PackageCopyrightText: NOASSERTION
ExternalRef: PACKAGE-MANAGER purl pkg:npm/%40orchard-example/router@2.1.3

##### Package: @orchard-example/http-core

PackageName: @orchard-example/http-core
SPDXID: SPDXRef-Package-orchard-example-http-core
PackageVersion: 1.8.0
PackageSupplier: Organization: Example Softworks (fictional)
PackageDownloadLocation: https://registry.orchard.example/@orchard-example/http-core/-/http-core-1.8.0.tgz
FilesAnalyzed: false
PackageChecksum: SHA256: 05dc223ec1875dfd80d8c5873f8c29f036f98587f2fe2d02abc7c718bfb4b8bf
PackageLicenseConcluded: MIT
PackageLicenseDeclared: MIT
PackageCopyrightText: NOASSERTION
ExternalRef: PACKAGE-MANAGER purl pkg:npm/%40orchard-example/http-core@1.8.0

##### Package: example-metrics

PackageName: example-metrics
SPDXID: SPDXRef-Package-example-metrics
PackageVersion: 4.0.0
PackageSupplier: Organization: Example Softworks (fictional)
PackageDownloadLocation: https://registry.orchard.example/example-metrics/-/example-metrics-4.0.0.tgz
FilesAnalyzed: false
PackageChecksum: SHA256: 4a8930c617fd12bb99d26e868224d9918e4a3e00f8dd26b876ed19eb6e664f73
PackageLicenseConcluded: MIT
PackageLicenseDeclared: MIT
PackageCopyrightText: NOASSERTION
ExternalRef: PACKAGE-MANAGER purl pkg:npm/example-metrics@4.0.0

##### Files

FileName: ./dist/gateway.js
SPDXID: SPDXRef-File-gateway-js
FileChecksum: SHA1: 1ebfca75b2b7ef03d6deb5a8cb9271a6de6c0bd8
FileChecksum: SHA256: c2d4f8f1a9ac6dc538147506d9ac5e9ab310f62cc30a744ec72ca21ab9997bd2
LicenseConcluded: Apache-2.0
LicenseInfoInFile: Apache-2.0
FileCopyrightText: NOASSERTION

FileName: ./dist/router.js
SPDXID: SPDXRef-File-router-js
FileChecksum: SHA1: a662985940c1759973bc0b8150242c1712864a36
FileChecksum: SHA256: b2fc3c1fd285c9582dc403a89794e2a2129e1fd3a1c54b728f23b2d476d7fe25
LicenseConcluded: Apache-2.0
LicenseInfoInFile: Apache-2.0
FileCopyrightText: NOASSERTION

Relationship: SPDXRef-Package-orchard-example-gateway CONTAINS SPDXRef-File-gateway-js
Relationship: SPDXRef-Package-orchard-example-gateway CONTAINS SPDXRef-File-router-js

##### Relationships

Relationship: SPDXRef-DOCUMENT DESCRIBES SPDXRef-Package-orchard-example-gateway
Relationship: SPDXRef-Package-orchard-example-gateway DEPENDS_ON SPDXRef-Package-orchard-example-router
Relationship: SPDXRef-Package-orchard-example-gateway DEPENDS_ON SPDXRef-Package-orchard-example-http-core
Relationship: SPDXRef-Package-orchard-example-gateway DEPENDS_ON SPDXRef-Package-example-metrics
