{
  "results": [
    {
      "source": {
        "path": "/workspace/package-lock.json",
        "type": "lockfile"
      },
      "packages": [
        {
          "package": {
            "name": "example-logger",
            "version": "3.4.1",
            "ecosystem": "npm"
          },
          "vulnerabilities": [
            {
              "schema_version": "1.6.0",
              "id": "NOVUS-SAMPLE-2026-0001",
              "modified": "2026-01-10T00:00:00Z",
              "published": "2026-01-05T00:00:00Z",
              "aliases": [
                "SAMPLE-CVE-2026-0001"
              ],
              "summary": "SAMPLE advisory: fabricated improper-input-validation issue in a fictional logging library.",
              "details": "SAMPLE advisory: fabricated improper-input-validation issue in a fictional logging library. This record exists only as a test fixture; the package, the advisory and the identifier are all invented.",
              "affected": [
                {
                  "package": {
                    "ecosystem": "npm",
                    "name": "example-logger",
                    "purl": "pkg:npm/example-logger@3.4.1"
                  },
                  "ranges": [
                    {
                      "type": "SEMVER",
                      "events": [
                        {
                          "introduced": "0"
                        },
                        {
                          "fixed": "3.5.0"
                        }
                      ]
                    }
                  ],
                  "versions": [
                    "3.4.1"
                  ],
                  "database_specific": {
                    "source": "NOVUS-SAMPLE",
                    "cwe": "CWE-20",
                    "vulnerable_range": "<3.5.0"
                  }
                }
              ],
              "severity": [
                {
                  "type": "CVSS_V3",
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
                }
              ],
              "references": [
                {
                  "type": "ADVISORY",
                  "url": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0001"
                },
                {
                  "type": "FIX",
                  "url": "https://git.orchard.example/logger/3.5.0"
                }
              ],
              "database_specific": {
                "severity": "HIGH",
                "cvss_score": 8.1,
                "note": "Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists."
              }
            }
          ],
          "groups": [
            {
              "ids": [
                "NOVUS-SAMPLE-2026-0001"
              ],
              "aliases": [
                "NOVUS-SAMPLE-2026-0001",
                "SAMPLE-CVE-2026-0001"
              ],
              "max_severity": "8.1"
            }
          ]
        },
        {
          "package": {
            "name": "example-cache",
            "version": "0.9.2",
            "ecosystem": "npm"
          },
          "vulnerabilities": [
            {
              "schema_version": "1.6.0",
              "id": "NOVUS-SAMPLE-2026-0002",
              "modified": "2026-01-10T00:00:00Z",
              "published": "2026-01-05T00:00:00Z",
              "aliases": [
                "SAMPLE-CVE-2026-0002"
              ],
              "summary": "SAMPLE advisory: fabricated unsafe-deserialisation issue in a fictional cache library.",
              "details": "SAMPLE advisory: fabricated unsafe-deserialisation issue in a fictional cache library. This record exists only as a test fixture; the package, the advisory and the identifier are all invented.",
              "affected": [
                {
                  "package": {
                    "ecosystem": "npm",
                    "name": "example-cache",
                    "purl": "pkg:npm/example-cache@0.9.2"
                  },
                  "ranges": [
                    {
                      "type": "SEMVER",
                      "events": [
                        {
                          "introduced": "0"
                        },
                        {
                          "fixed": "0.9.5"
                        }
                      ]
                    }
                  ],
                  "versions": [
                    "0.9.2"
                  ],
                  "database_specific": {
                    "source": "NOVUS-SAMPLE",
                    "cwe": "CWE-502",
                    "vulnerable_range": ">=0.9.0 <0.9.5"
                  }
                }
              ],
              "severity": [
                {
                  "type": "CVSS_V3",
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
                }
              ],
              "references": [
                {
                  "type": "ADVISORY",
                  "url": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0002"
                },
                {
                  "type": "FIX",
                  "url": "https://git.orchard.example/cache/0.9.5"
                }
              ],
              "database_specific": {
                "severity": "CRITICAL",
                "cvss_score": 9.3,
                "note": "Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists."
              }
            }
          ],
          "groups": [
            {
              "ids": [
                "NOVUS-SAMPLE-2026-0002"
              ],
              "aliases": [
                "NOVUS-SAMPLE-2026-0002",
                "SAMPLE-CVE-2026-0002"
              ],
              "max_severity": "9.3"
            }
          ]
        },
        {
          "package": {
            "name": "example-yaml-lite",
            "version": "1.1.7",
            "ecosystem": "npm"
          },
          "vulnerabilities": [
            {
              "schema_version": "1.6.0",
              "id": "NOVUS-SAMPLE-2026-0003",
              "modified": "2026-01-10T00:00:00Z",
              "published": "2026-01-05T00:00:00Z",
              "aliases": [
                "SAMPLE-CVE-2026-0003"
              ],
              "summary": "SAMPLE advisory: fabricated uncontrolled-resource-consumption issue in a fictional parser.",
              "details": "SAMPLE advisory: fabricated uncontrolled-resource-consumption issue in a fictional parser. This record exists only as a test fixture; the package, the advisory and the identifier are all invented.",
              "affected": [
                {
                  "package": {
                    "ecosystem": "npm",
                    "name": "example-yaml-lite",
                    "purl": "pkg:npm/example-yaml-lite@1.1.7"
                  },
                  "ranges": [
                    {
                      "type": "SEMVER",
                      "events": [
                        {
                          "introduced": "0"
                        },
                        {
                          "fixed": "1.2.0"
                        }
                      ]
                    }
                  ],
                  "versions": [
                    "1.1.7"
                  ],
                  "database_specific": {
                    "source": "NOVUS-SAMPLE",
                    "cwe": "CWE-400",
                    "vulnerable_range": "<1.2.0"
                  }
                }
              ],
              "severity": [
                {
                  "type": "CVSS_V3",
                  "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
              ],
              "references": [
                {
                  "type": "ADVISORY",
                  "url": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0003"
                },
                {
                  "type": "FIX",
                  "url": "https://git.orchard.example/yamllite/1.2.0"
                }
              ],
              "database_specific": {
                "severity": "MEDIUM",
                "cvss_score": 5.4,
                "note": "Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists."
              }
            }
          ],
          "groups": [
            {
              "ids": [
                "NOVUS-SAMPLE-2026-0003"
              ],
              "aliases": [
                "NOVUS-SAMPLE-2026-0003",
                "SAMPLE-CVE-2026-0003"
              ],
              "max_severity": "5.4"
            }
          ]
        },
        {
          "package": {
            "name": "example-json-path",
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          "vulnerabilities": [
            {
              "schema_version": "1.6.0",
              "id": "NOVUS-SAMPLE-2026-0004",
              "modified": "2026-01-10T00:00:00Z",
              "published": "2026-01-05T00:00:00Z",
              "aliases": [
                "SAMPLE-CVE-2026-0004"
              ],
              "summary": "SAMPLE advisory: fabricated allocation-without-limits issue in a fictional query library.",
              "details": "SAMPLE advisory: fabricated allocation-without-limits issue in a fictional query library. This record exists only as a test fixture; the package, the advisory and the identifier are all invented.",
              "affected": [
                {
                  "package": {
                    "ecosystem": "npm",
                    "name": "example-json-path",
                    "purl": "pkg:npm/example-json-path@2.0.5"
                  },
                  "ranges": [
                    {
                      "type": "SEMVER",
                      "events": [
                        {
                          "introduced": "0"
                        },
                        {
                          "fixed": "2.1.0"
                        }
                      ]
                    }
                  ],
                  "versions": [
                    "2.0.5"
                  ],
                  "database_specific": {
                    "source": "NOVUS-SAMPLE",
                    "cwe": "CWE-770",
                    "vulnerable_range": "<2.1.0"
                  }
                }
              ],
              "severity": [
                {
                  "type": "CVSS_V3",
                  "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L"
                }
              ],
              "references": [
                {
                  "type": "ADVISORY",
                  "url": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0004"
                },
                {
                  "type": "FIX",
                  "url": "https://git.orchard.example/jsonpath/2.1.0"
                }
              ],
              "database_specific": {
                "severity": "LOW",
                "cvss_score": 3.1,
                "note": "Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists."
              }
            }
          ],
          "groups": [
            {
              "ids": [
                "NOVUS-SAMPLE-2026-0004"
              ],
              "aliases": [
                "NOVUS-SAMPLE-2026-0004",
                "SAMPLE-CVE-2026-0004"
              ],
              "max_severity": "3.1"
            }
          ]
        }
      ]
    }
  ],
  "experimental_config": {
    "licenses": {
      "summary": false,
      "allowlist": []
    }
  },
  "novus_sample_note": "Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists."
}
