{
  "SchemaVersion": 2,
  "CreatedAt": "2026-01-01T00:00:00Z",
  "ArtifactName": ".",
  "ArtifactType": "filesystem",
  "Metadata": {
    "ImageConfig": {}
  },
  "Results": [
    {
      "Target": "package-lock.json",
      "Class": "lang-pkgs",
      "Type": "npm",
      "Vulnerabilities": [
        {
          "VulnerabilityID": "NOVUS-SAMPLE-2026-0001",
          "PkgName": "example-logger",
          "PkgIdentifier": {
            "PURL": "pkg:npm/example-logger@3.4.1"
          },
          "InstalledVersion": "3.4.1",
          "FixedVersion": "3.5.0",
          "Status": "fixed",
          "SeveritySource": "novus-sample",
          "PrimaryURL": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0001",
          "Title": "SAMPLE advisory: fabricated improper-input-validation issue in a fictional logging library.",
          "Description": "SAMPLE advisory: fabricated improper-input-validation issue in a fictional logging library. Published only as a test fixture.",
          "Severity": "HIGH",
          "CweIDs": [
            "CWE-20"
          ],
          "VendorSeverity": {
            "novus-sample": 3
          },
          "CVSS": {
            "novus-sample": {
              "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "V3Score": 8.1
            }
          },
          "References": [
            "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0001",
            "https://git.orchard.example/logger/releases/3.5.0"
          ],
          "PublishedDate": "2026-01-05T00:00:00Z",
          "LastModifiedDate": "2026-01-10T00:00:00Z",
          "DataSource": {
            "ID": "novus-sample",
            "Name": "Novus SAMPLE advisory feed",
            "URL": "https://advisories.orchard.example"
          }
        },
        {
          "VulnerabilityID": "NOVUS-SAMPLE-2026-0002",
          "PkgName": "example-cache",
          "PkgIdentifier": {
            "PURL": "pkg:npm/example-cache@0.9.2"
          },
          "InstalledVersion": "0.9.2",
          "FixedVersion": "0.9.5",
          "Status": "fixed",
          "SeveritySource": "novus-sample",
          "PrimaryURL": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0002",
          "Title": "SAMPLE advisory: fabricated unsafe-deserialisation issue in a fictional cache library.",
          "Description": "SAMPLE advisory: fabricated unsafe-deserialisation issue in a fictional cache library. Published only as a test fixture.",
          "Severity": "CRITICAL",
          "CweIDs": [
            "CWE-502"
          ],
          "VendorSeverity": {
            "novus-sample": 4
          },
          "CVSS": {
            "novus-sample": {
              "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
              "V3Score": 9.3
            }
          },
          "References": [
            "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0002",
            "https://git.orchard.example/cache/releases/0.9.5"
          ],
          "PublishedDate": "2026-01-05T00:00:00Z",
          "LastModifiedDate": "2026-01-10T00:00:00Z",
          "DataSource": {
            "ID": "novus-sample",
            "Name": "Novus SAMPLE advisory feed",
            "URL": "https://advisories.orchard.example"
          }
        },
        {
          "VulnerabilityID": "NOVUS-SAMPLE-2026-0003",
          "PkgName": "example-yaml-lite",
          "PkgIdentifier": {
            "PURL": "pkg:npm/example-yaml-lite@1.1.7"
          },
          "InstalledVersion": "1.1.7",
          "FixedVersion": "1.2.0",
          "Status": "fixed",
          "SeveritySource": "novus-sample",
          "PrimaryURL": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0003",
          "Title": "SAMPLE advisory: fabricated uncontrolled-resource-consumption issue in a fictional parser.",
          "Description": "SAMPLE advisory: fabricated uncontrolled-resource-consumption issue in a fictional parser. Published only as a test fixture.",
          "Severity": "MEDIUM",
          "CweIDs": [
            "CWE-400"
          ],
          "VendorSeverity": {
            "novus-sample": 2
          },
          "CVSS": {
            "novus-sample": {
              "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "V3Score": 5.4
            }
          },
          "References": [
            "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0003",
            "https://git.orchard.example/yamllite/releases/1.2.0"
          ],
          "PublishedDate": "2026-01-05T00:00:00Z",
          "LastModifiedDate": "2026-01-10T00:00:00Z",
          "DataSource": {
            "ID": "novus-sample",
            "Name": "Novus SAMPLE advisory feed",
            "URL": "https://advisories.orchard.example"
          }
        },
        {
          "VulnerabilityID": "NOVUS-SAMPLE-2026-0004",
          "PkgName": "example-json-path",
          "PkgIdentifier": {
            "PURL": "pkg:npm/example-json-path@2.0.5"
          },
          "InstalledVersion": "2.0.5",
          "FixedVersion": "2.1.0",
          "Status": "fixed",
          "SeveritySource": "novus-sample",
          "PrimaryURL": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0004",
          "Title": "SAMPLE advisory: fabricated allocation-without-limits issue in a fictional query library.",
          "Description": "SAMPLE advisory: fabricated allocation-without-limits issue in a fictional query library. Published only as a test fixture.",
          "Severity": "LOW",
          "CweIDs": [
            "CWE-770"
          ],
          "VendorSeverity": {
            "novus-sample": 1
          },
          "CVSS": {
            "novus-sample": {
              "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L",
              "V3Score": 3.1
            }
          },
          "References": [
            "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0004",
            "https://git.orchard.example/jsonpath/releases/2.1.0"
          ],
          "PublishedDate": "2026-01-05T00:00:00Z",
          "LastModifiedDate": "2026-01-10T00:00:00Z",
          "DataSource": {
            "ID": "novus-sample",
            "Name": "Novus SAMPLE advisory feed",
            "URL": "https://advisories.orchard.example"
          }
        }
      ]
    }
  ],
  "novus_sample_note": "Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists."
}
