{
  "reportSchema": "1.1",
  "scanInfo": {
    "engineVersion": "0.0.0-sample"
  },
  "projectInfo": {
    "name": "orchard-gateway",
    "reportDate": "2026-01-01T00:00:00Z",
    "credits": {
      "NOVUS-SAMPLE": "Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists."
    }
  },
  "dependencies": [
    {
      "isVirtual": false,
      "fileName": "example-logger-3.4.1.tgz",
      "filePath": "/app/node_modules/example-logger",
      "sha256": "7fb72ea58987e5327259b66384f96f5e657c3ce5225b8891c567cac6b58430ec",
      "evidenceCollected": {
        "vendorEvidence": [
          {
            "type": "vendor",
            "confidence": "HIGH",
            "source": "package.json",
            "name": "author",
            "value": "Example Softworks (fictional)"
          }
        ]
      },
      "packages": [
        {
          "id": "pkg:npm/example-logger@3.4.1",
          "confidence": "HIGHEST",
          "url": "https://advisories.orchard.example"
        }
      ],
      "vulnerabilities": [
        {
          "source": "NOVUS-SAMPLE",
          "name": "NOVUS-SAMPLE-2026-0001",
          "severity": "HIGH",
          "cvssv3": {
            "baseScore": 8.1,
            "attackVector": "NETWORK",
            "baseSeverity": "HIGH"
          },
          "cwes": [
            "CWE-20"
          ],
          "description": "SAMPLE advisory: fabricated improper-input-validation issue in a fictional logging library.",
          "notes": "SAMPLE finding — fixture only.",
          "references": [
            {
              "source": "NOVUS-SAMPLE",
              "url": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0001",
              "name": "NOVUS-SAMPLE-2026-0001"
            }
          ],
          "vulnerableSoftware": [
            {
              "software": {
                "id": "pkg:npm/example-logger@3.4.1",
                "versionEndExcluding": "3.5.0"
              }
            }
          ]
        }
      ]
    },
    {
      "isVirtual": false,
      "fileName": "example-cache-0.9.2.tgz",
      "filePath": "/app/node_modules/example-cache",
      "sha256": "f7af2ad2d3c3daaa5991b0eae38ffa151a2e2f3bf0f2bdd7333adc3a1dc860f7",
      "evidenceCollected": {
        "vendorEvidence": [
          {
            "type": "vendor",
            "confidence": "HIGH",
            "source": "package.json",
            "name": "author",
            "value": "Example Softworks (fictional)"
          }
        ]
      },
      "packages": [
        {
          "id": "pkg:npm/example-cache@0.9.2",
          "confidence": "HIGHEST",
          "url": "https://advisories.orchard.example"
        }
      ],
      "vulnerabilities": [
        {
          "source": "NOVUS-SAMPLE",
          "name": "NOVUS-SAMPLE-2026-0002",
          "severity": "CRITICAL",
          "cvssv3": {
            "baseScore": 9.3,
            "attackVector": "NETWORK",
            "baseSeverity": "CRITICAL"
          },
          "cwes": [
            "CWE-502"
          ],
          "description": "SAMPLE advisory: fabricated unsafe-deserialisation issue in a fictional cache library.",
          "notes": "SAMPLE finding — fixture only.",
          "references": [
            {
              "source": "NOVUS-SAMPLE",
              "url": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0002",
              "name": "NOVUS-SAMPLE-2026-0002"
            }
          ],
          "vulnerableSoftware": [
            {
              "software": {
                "id": "pkg:npm/example-cache@0.9.2",
                "versionEndExcluding": "0.9.5"
              }
            }
          ]
        }
      ]
    },
    {
      "isVirtual": false,
      "fileName": "example-yaml-lite-1.1.7.tgz",
      "filePath": "/app/node_modules/example-yaml-lite",
      "sha256": "d7094de3c8e15621381e5f9f02c0eecb9977d249a8a06ab2b0a34f5344a039af",
      "evidenceCollected": {
        "vendorEvidence": [
          {
            "type": "vendor",
            "confidence": "HIGH",
            "source": "package.json",
            "name": "author",
            "value": "Example Softworks (fictional)"
          }
        ]
      },
      "packages": [
        {
          "id": "pkg:npm/example-yaml-lite@1.1.7",
          "confidence": "HIGHEST",
          "url": "https://advisories.orchard.example"
        }
      ],
      "vulnerabilities": [
        {
          "source": "NOVUS-SAMPLE",
          "name": "NOVUS-SAMPLE-2026-0003",
          "severity": "MEDIUM",
          "cvssv3": {
            "baseScore": 5.4,
            "attackVector": "NETWORK",
            "baseSeverity": "MEDIUM"
          },
          "cwes": [
            "CWE-400"
          ],
          "description": "SAMPLE advisory: fabricated uncontrolled-resource-consumption issue in a fictional parser.",
          "notes": "SAMPLE finding — fixture only.",
          "references": [
            {
              "source": "NOVUS-SAMPLE",
              "url": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0003",
              "name": "NOVUS-SAMPLE-2026-0003"
            }
          ],
          "vulnerableSoftware": [
            {
              "software": {
                "id": "pkg:npm/example-yaml-lite@1.1.7",
                "versionEndExcluding": "1.2.0"
              }
            }
          ]
        }
      ]
    },
    {
      "isVirtual": false,
      "fileName": "example-json-path-2.0.5.tgz",
      "filePath": "/app/node_modules/example-json-path",
      "sha256": "74e30e4812a0cc92bd7c1a965e6f953f5d92b9eaf3cd77d90663a7344e939b63",
      "evidenceCollected": {
        "vendorEvidence": [
          {
            "type": "vendor",
            "confidence": "HIGH",
            "source": "package.json",
            "name": "author",
            "value": "Example Softworks (fictional)"
          }
        ]
      },
      "packages": [
        {
          "id": "pkg:npm/example-json-path@2.0.5",
          "confidence": "HIGHEST",
          "url": "https://advisories.orchard.example"
        }
      ],
      "vulnerabilities": [
        {
          "source": "NOVUS-SAMPLE",
          "name": "NOVUS-SAMPLE-2026-0004",
          "severity": "LOW",
          "cvssv3": {
            "baseScore": 3.1,
            "attackVector": "NETWORK",
            "baseSeverity": "LOW"
          },
          "cwes": [
            "CWE-770"
          ],
          "description": "SAMPLE advisory: fabricated allocation-without-limits issue in a fictional query library.",
          "notes": "SAMPLE finding — fixture only.",
          "references": [
            {
              "source": "NOVUS-SAMPLE",
              "url": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0004",
              "name": "NOVUS-SAMPLE-2026-0004"
            }
          ],
          "vulnerableSoftware": [
            {
              "software": {
                "id": "pkg:npm/example-json-path@2.0.5",
                "versionEndExcluding": "2.1.0"
              }
            }
          ]
        }
      ]
    }
  ]
}
