{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "title": "SAMPLE VEX for Orchard Gateway 4.2.0 (fictional)",
    "publisher": {
      "category": "vendor",
      "name": "Example Softworks (fictional)",
      "namespace": "https://orchard.example"
    },
    "tracking": {
      "id": "ORCHARD-SAMPLE-VEX-0001",
      "status": "final",
      "version": "1",
      "initial_release_date": "2026-01-01T00:00:00Z",
      "current_release_date": "2026-01-01T00:00:00Z",
      "generator": {
        "engine": {
          "name": "novus-examples-vex-fixture",
          "version": "1.0.0"
        }
      },
      "revision_history": [
        {
          "number": "1",
          "date": "2026-01-01T00:00:00Z",
          "summary": "Initial SAMPLE release."
        }
      ]
    },
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.",
        "title": "SAMPLE data"
      }
    ]
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Example Softworks (fictional)",
        "branches": [
          {
            "category": "product_name",
            "name": "orchard-gateway",
            "branches": [
              {
                "category": "product_version",
                "name": "4.2.0",
                "product": {
                  "name": "orchard-gateway 4.2.0",
                  "product_id": "CSAFPID-0001",
                  "product_identification_helper": {
                    "purl": "pkg:npm/%40orchard-example/gateway@4.2.0"
                  }
                }
              }
            ]
          }
        ]
      }
    ]
  },
  "vulnerabilities": [
    {
      "ids": [
        {
          "system_name": "NOVUS-SAMPLE advisory feed",
          "text": "NOVUS-SAMPLE-2026-0001"
        },
        {
          "system_name": "SAMPLE alias",
          "text": "SAMPLE-CVE-2026-0001"
        }
      ],
      "title": "SAMPLE advisory: fabricated improper-input-validation issue in a fictional logging library.",
      "notes": [
        {
          "category": "description",
          "text": "SAMPLE advisory: fabricated improper-input-validation issue in a fictional logging library.",
          "title": "SAMPLE"
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-0001"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Upgrade example-logger to 3.5.0.",
          "product_ids": [
            "CSAFPID-0001"
          ]
        }
      ]
    },
    {
      "ids": [
        {
          "system_name": "NOVUS-SAMPLE advisory feed",
          "text": "NOVUS-SAMPLE-2026-0002"
        },
        {
          "system_name": "SAMPLE alias",
          "text": "SAMPLE-CVE-2026-0002"
        }
      ],
      "title": "SAMPLE advisory: fabricated unsafe-deserialisation issue in a fictional cache library.",
      "notes": [
        {
          "category": "description",
          "text": "SAMPLE advisory: fabricated unsafe-deserialisation issue in a fictional cache library.",
          "title": "SAMPLE"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "CSAFPID-0001"
        ]
      },
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "CSAFPID-0001"
          ]
        }
      ]
    },
    {
      "ids": [
        {
          "system_name": "NOVUS-SAMPLE advisory feed",
          "text": "NOVUS-SAMPLE-2026-0003"
        },
        {
          "system_name": "SAMPLE alias",
          "text": "SAMPLE-CVE-2026-0003"
        }
      ],
      "title": "SAMPLE advisory: fabricated uncontrolled-resource-consumption issue in a fictional parser.",
      "notes": [
        {
          "category": "description",
          "text": "SAMPLE advisory: fabricated uncontrolled-resource-consumption issue in a fictional parser.",
          "title": "SAMPLE"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-0001"
        ]
      }
    },
    {
      "ids": [
        {
          "system_name": "NOVUS-SAMPLE advisory feed",
          "text": "NOVUS-SAMPLE-2026-0004"
        },
        {
          "system_name": "SAMPLE alias",
          "text": "SAMPLE-CVE-2026-0004"
        }
      ],
      "title": "SAMPLE advisory: fabricated allocation-without-limits issue in a fictional query library.",
      "notes": [
        {
          "category": "description",
          "text": "SAMPLE advisory: fabricated allocation-without-limits issue in a fictional query library.",
          "title": "SAMPLE"
        }
      ],
      "product_status": {
        "under_investigation": [
          "CSAFPID-0001"
        ]
      }
    }
  ]
}
