Skip to content
Novus Examples
json3.7 KB

npm-shrinkwrap.json (Publishable Lock)

The shrinkwrap variant of an npm lockfile — identical in structure to package-lock.json but published inside the package tarball, so tooling that keys on the filename must handle both. Every package, version, hash and licence is fictional — the tree describes nothing real.

Preview — first 50 linesjson
{
  "name": "orchard-gateway",
  "version": "4.2.0",
  "lockfileVersion": 3,
  "requires": true,
  "packages": {
    "": {
      "name": "orchard-gateway",
      "version": "4.2.0",
      "license": "Apache-2.0",
      "dependencies": {
        "@orchard-example/router": "^2.1.0",
        "@orchard-example/http-core": "^1.8.0",
        "example-metrics": "^4.0.0",
        "example-cache": "^0.9.0",
        "example-crypto-shim": "^1.2.0"
      },
      "engines": {
        "node": ">=20.9"
      }
    },
    "node_modules/@orchard-example/router": {
      "version": "2.1.3",
      "resolved": "https://registry.orchard.example/@orchard-example/router/-/router-2.1.3.tgz",
      "integrity": "sha512-qtnM4l9j8zUuqQ9ICsxCdfl879PtducHYPiqO151qEu6bBv48+zuYbTbn/vSTJGbCd2RvGpDry/NEkSe1babaA==",
      "license": "Apache-2.0",
      "dependencies": {
        "example-logger": "^3.4.0",
        "example-retry": "^1.0.0"
      }
    },
    "node_modules/@orchard-example/http-core": {
      "version": "1.8.0",
      "resolved": "https://registry.orchard.example/@orchard-example/http-core/-/http-core-1.8.0.tgz",
      "integrity": "sha512-fG9AJmG+37+sln/eMVPmbu/bIcV+QbJ3bibSV9ob8PV6GYNFinrhSJQYFxkEYEHxckXBn7ExDim59rqSDaYoFg==",
      "license": "MIT",
      "dependencies": {
        "example-logger": "^3.4.0",
        "example-json-path": "^2.0.0"
      }
    },
    "node_modules/example-metrics": {
      "version": "4.0.0",
      "resolved": "https://registry.orchard.example/example-metrics/-/example-metrics-4.0.0.tgz",
      "integrity": "sha512-Sq3cxZ+Brv4bgLd+5B/o3upQ1O6YKjbr6TP5ZBZfw4XVjna6/8YkOeB52iLhrRDjs1UiF5v20Ijr7bEJtHKcOQ==",
      "license": "MIT",
      "dependencies": {
        "example-logger": "^3.4.0"
      }
    },
95 lines total — download for the full file.

Specifications

Seed
51200
Sample Only
true
Ecosystem
npm
Lockfile Version
3
Publishable
true
Line Endings
LF

Testing contract

Expected to pass
Scenario
Detect a lockfile by content rather than by filename.
Expected result
The shrinkwrap parses through the same code path as package-lock.json and yields an identical 9-package tree.

What is a .json file?

JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.

How to use this file

Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.

How to use this file for testing

“npm-shrinkwrap.json (Publishable Lock)” is a deterministic Novus Examples fixture for JSON parsing, Conversion testing. Flat, deeply nested, JSON Lines, and intentionally invalid JSON for testing parsers and error handling.

Documented properties for this file: seed 51200 · LF. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.

Feed the file to your parser and assert it handles the documented quirks — quoted delimiters, embedded newlines, ragged rows, or invalid syntax; the valid↔invalid distinction is labelled in the title.

Code examples

import json

with open("npm-shrinkwrap.json") as f:
    data = json.load(f)
print(type(data), len(data))

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.