{
  "SchemaVersion": 2,
  "CreatedAt": "2026-01-01T00:00:00Z",
  "ArtifactName": "registry.orchard.example/orchard/gateway:4.2.0",
  "ArtifactType": "container_image",
  "Metadata": {
    "OS": {
      "Family": "example-linux",
      "Name": "3.20"
    },
    "ImageID": "sha256:d09edb133f6122a6ada56f6e62db4a1d0a2fa4faef6aa8948b1aad1c9b49eb76",
    "DiffIDs": [
      "sha256:bd0e7eed492c370c64bbe5350623680eb433f858980a225d4ab53fc345a6f143",
      "sha256:b644115ef371067688ed39896d1a798e5a7bf3a09ca10c0d94a3f6a9b4c1aae7"
    ],
    "RepoTags": [
      "registry.orchard.example/orchard/gateway:4.2.0"
    ]
  },
  "Results": [
    {
      "Target": "registry.orchard.example/orchard/gateway:4.2.0 (example-linux 3.20)",
      "Class": "os-pkgs",
      "Type": "example-linux",
      "Vulnerabilities": [
        {
          "VulnerabilityID": "NOVUS-SAMPLE-2026-0001",
          "PkgName": "example-logger",
          "PkgIdentifier": {
            "PURL": "pkg:npm/example-logger@3.4.1"
          },
          "InstalledVersion": "3.4.1",
          "FixedVersion": "3.5.0",
          "Status": "fixed",
          "SeveritySource": "novus-sample",
          "PrimaryURL": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0001",
          "Title": "SAMPLE advisory: fabricated improper-input-validation issue in a fictional logging library.",
          "Description": "SAMPLE advisory: fabricated improper-input-validation issue in a fictional logging library. Published only as a test fixture.",
          "Severity": "HIGH",
          "CweIDs": [
            "CWE-20"
          ],
          "VendorSeverity": {
            "novus-sample": 3
          },
          "CVSS": {
            "novus-sample": {
              "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "V3Score": 8.1
            }
          },
          "References": [
            "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0001",
            "https://git.orchard.example/logger/releases/3.5.0"
          ],
          "PublishedDate": "2026-01-05T00:00:00Z",
          "LastModifiedDate": "2026-01-10T00:00:00Z",
          "DataSource": {
            "ID": "novus-sample",
            "Name": "Novus SAMPLE advisory feed",
            "URL": "https://advisories.orchard.example"
          }
        },
        {
          "VulnerabilityID": "NOVUS-SAMPLE-2026-0002",
          "PkgName": "example-cache",
          "PkgIdentifier": {
            "PURL": "pkg:npm/example-cache@0.9.2"
          },
          "InstalledVersion": "0.9.2",
          "FixedVersion": "0.9.5",
          "Status": "fixed",
          "SeveritySource": "novus-sample",
          "PrimaryURL": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0002",
          "Title": "SAMPLE advisory: fabricated unsafe-deserialisation issue in a fictional cache library.",
          "Description": "SAMPLE advisory: fabricated unsafe-deserialisation issue in a fictional cache library. Published only as a test fixture.",
          "Severity": "CRITICAL",
          "CweIDs": [
            "CWE-502"
          ],
          "VendorSeverity": {
            "novus-sample": 4
          },
          "CVSS": {
            "novus-sample": {
              "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
              "V3Score": 9.3
            }
          },
          "References": [
            "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0002",
            "https://git.orchard.example/cache/releases/0.9.5"
          ],
          "PublishedDate": "2026-01-05T00:00:00Z",
          "LastModifiedDate": "2026-01-10T00:00:00Z",
          "DataSource": {
            "ID": "novus-sample",
            "Name": "Novus SAMPLE advisory feed",
            "URL": "https://advisories.orchard.example"
          }
        }
      ]
    },
    {
      "Target": "app/package-lock.json",
      "Class": "lang-pkgs",
      "Type": "npm",
      "Vulnerabilities": [
        {
          "VulnerabilityID": "NOVUS-SAMPLE-2026-0003",
          "PkgName": "example-yaml-lite",
          "PkgIdentifier": {
            "PURL": "pkg:npm/example-yaml-lite@1.1.7"
          },
          "InstalledVersion": "1.1.7",
          "FixedVersion": "1.2.0",
          "Status": "fixed",
          "SeveritySource": "novus-sample",
          "PrimaryURL": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0003",
          "Title": "SAMPLE advisory: fabricated uncontrolled-resource-consumption issue in a fictional parser.",
          "Description": "SAMPLE advisory: fabricated uncontrolled-resource-consumption issue in a fictional parser. Published only as a test fixture.",
          "Severity": "MEDIUM",
          "CweIDs": [
            "CWE-400"
          ],
          "VendorSeverity": {
            "novus-sample": 2
          },
          "CVSS": {
            "novus-sample": {
              "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "V3Score": 5.4
            }
          },
          "References": [
            "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0003",
            "https://git.orchard.example/yamllite/releases/1.2.0"
          ],
          "PublishedDate": "2026-01-05T00:00:00Z",
          "LastModifiedDate": "2026-01-10T00:00:00Z",
          "DataSource": {
            "ID": "novus-sample",
            "Name": "Novus SAMPLE advisory feed",
            "URL": "https://advisories.orchard.example"
          }
        },
        {
          "VulnerabilityID": "NOVUS-SAMPLE-2026-0004",
          "PkgName": "example-json-path",
          "PkgIdentifier": {
            "PURL": "pkg:npm/example-json-path@2.0.5"
          },
          "InstalledVersion": "2.0.5",
          "FixedVersion": "2.1.0",
          "Status": "fixed",
          "SeveritySource": "novus-sample",
          "PrimaryURL": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0004",
          "Title": "SAMPLE advisory: fabricated allocation-without-limits issue in a fictional query library.",
          "Description": "SAMPLE advisory: fabricated allocation-without-limits issue in a fictional query library. Published only as a test fixture.",
          "Severity": "LOW",
          "CweIDs": [
            "CWE-770"
          ],
          "VendorSeverity": {
            "novus-sample": 1
          },
          "CVSS": {
            "novus-sample": {
              "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L",
              "V3Score": 3.1
            }
          },
          "References": [
            "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0004",
            "https://git.orchard.example/jsonpath/releases/2.1.0"
          ],
          "PublishedDate": "2026-01-05T00:00:00Z",
          "LastModifiedDate": "2026-01-10T00:00:00Z",
          "DataSource": {
            "ID": "novus-sample",
            "Name": "Novus SAMPLE advisory feed",
            "URL": "https://advisories.orchard.example"
          }
        }
      ]
    },
    {
      "Target": "app/config",
      "Class": "config",
      "Type": "dockerfile",
      "Misconfigurations": [
        {
          "Type": "Dockerfile Security Check",
          "ID": "SAMPLE-DS001",
          "Title": "SAMPLE: image runs as root",
          "Severity": "HIGH",
          "Status": "FAIL",
          "Message": "Fictional misconfiguration used only as a fixture."
        }
      ]
    }
  ],
  "novus_sample_note": "Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists."
}
