npm package-lock.json (lockfileVersion 1, Legacy)
The original npm v1 lockfile layout — a nested dependencies object with requires maps and no packages section — still found in long-lived repositories and needed by any migration path. Every package, version, hash and licence is fictional — the tree describes nothing real.
{
"name": "orchard-gateway",
"version": "4.2.0",
"lockfileVersion": 1,
"requires": true,
"dependencies": {
"@orchard-example/router": {
"version": "2.1.3",
"resolved": "https://registry.orchard.example/@orchard-example/router/-/router-2.1.3.tgz",
"integrity": "sha512-qtnM4l9j8zUuqQ9ICsxCdfl879PtducHYPiqO151qEu6bBv48+zuYbTbn/vSTJGbCd2RvGpDry/NEkSe1babaA==",
"requires": {
"example-logger": "^3.4.0",
"example-retry": "^1.0.0"
}
},
"@orchard-example/http-core": {
"version": "1.8.0",
"resolved": "https://registry.orchard.example/@orchard-example/http-core/-/http-core-1.8.0.tgz",
"integrity": "sha512-fG9AJmG+37+sln/eMVPmbu/bIcV+QbJ3bibSV9ob8PV6GYNFinrhSJQYFxkEYEHxckXBn7ExDim59rqSDaYoFg==",
"requires": {
"example-logger": "^3.4.0",
"example-json-path": "^2.0.0"
}
},
"example-metrics": {
"version": "4.0.0",
"resolved": "https://registry.orchard.example/example-metrics/-/example-metrics-4.0.0.tgz",
"integrity": "sha512-Sq3cxZ+Brv4bgLd+5B/o3upQ1O6YKjbr6TP5ZBZfw4XVjna6/8YkOeB52iLhrRDjs1UiF5v20Ijr7bEJtHKcOQ==",
"requires": {
"example-logger": "^3.4.0"
}
},
"example-cache": {
"version": "0.9.2",
"resolved": "https://registry.orchard.example/example-cache/-/example-cache-0.9.2.tgz",
"integrity": "sha512-AfwdCZmLEAUsc7Xx0ze+X4cSz6ES8G63hh3Jwx7mHEBJUNpzRLZBq7fDYVk7+cVh9spu+3wey8a0VDJS6cEpTw==",
"requires": {
"example-yaml-lite": "^1.1.0"
}
},
"example-crypto-shim": {
"version": "1.2.0",
"resolved": "https://registry.orchard.example/example-crypto-shim/-/example-crypto-shim-1.2.0.tgz",
"integrity": "sha512-C9iqJP6f/S7V/NsRGHnVv/u2nPtnjFMJbs4p8tMbjRSxrHeEjl6APolSniPvMFH0jlDUuO06nb86/a/GDEWRKg=="
},
"example-logger": {
"version": "3.4.1",
"resolved": "https://registry.orchard.example/example-logger/-/example-logger-3.4.1.tgz",
"integrity": "sha512-kk/Leb1fYZthao23OX82Smci+JVca/5L0WYLNiApltZN7GOWc6rnxGKDixrxNQHddbyLPlE2DjE4gkWFRIeaFw==",
"dev": falseSpecifications
- Seed
- 51200
- Sample Only
- true
- Ecosystem
- npm
- Lockfile Version
- 1
- Sections
- dependencies only
- Line Endings
- LF
Testing contract
Expected to pass- Scenario
- Upgrade a v1 lockfile to v3, or read it with a modern parser.
- Expected result
- The same 9 fictional packages and their integrity hashes survive, keyed by name rather than by node_modules path.
What is a .json file?
JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.
How to use this file
Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.
How to use this file for testing
“npm package-lock.json (lockfileVersion 1, Legacy)” is a deterministic Novus Examples fixture for JSON parsing, Conversion testing. Flat, deeply nested, JSON Lines, and intentionally invalid JSON for testing parsers and error handling.
Documented properties for this file: seed 51200 · LF. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.
Feed the file to your parser and assert it handles the documented quirks — quoted delimiters, embedded newlines, ragged rows, or invalid syntax; the valid↔invalid distinction is labelled in the title.
Code examples
import json
with open("package-lock-v1.json") as f:
data = json.load(f)
print(type(data), len(data))Related files
- lockbun.lock (Text Lockfile)Bun's text lockfile, where each package is a positional array of descriptor, dependency map and integrity string rather than an object — a shape that breaks parsers assuming every lock entry is keyed. Every package, version, hash and licence is fictional — the tree describes nothing real.

- lockcomposer.lock (PHP)A PHP composer.lock in JSON, pinning each fictional package by both a git reference and a dist zip shasum, with a content-hash binding it to composer.json. Every package, version, hash and licence is fictional — the tree describes nothing real.

- jsonpackages.lock.json (NuGet)A NuGet lockfile keyed by target framework, distinguishing Direct from Transitive entries and recording a base64 contentHash for each fictional package. Every package, version, hash and licence is fictional — the tree describes nothing real.

- lockPipfile.lock (Pipenv)A Pipenv lockfile in JSON, with the _meta hash that ties it to its Pipfile, a named index source and nine fictional pinned packages in the default section. Every package, version, hash and licence is fictional — the tree describes nothing real.

- jsonAttestation With a Full SPDX PredicateAn in-toto statement whose predicate is an entire SPDX 2.3 document — the nesting that makes attestation payloads large and that a size-limited verifier has to cope with. Every package, version, hash and licence is fictional — the tree describes nothing real.

- jsoncargo-audit Report (JSON)A cargo-audit report that shows three findings while a fourth is on the ignore list, plus an unmaintained-crate warning — so a gate must decide whether warnings count against it. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.