DSSE Envelope With Undecodable Payload — Intentionally Corrupt
An intentionally corrupt DSSE envelope: the JSON parses and the signature block looks complete, but the payload is truncated and contains characters outside the base64 alphabet. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.
{
"payloadType": "application/vnd.in-toto+json",
"payload": "eyJfdHlwZSI6Imh0dHBzOi8vaW4tdG90by5pby9TdGF0ZW1lbnQvdjEiLCJzdWJqZWN0IjpbeyJuYW1lIjoib3JjaGFyZC1nYXRld2F5LTQuMi4wLnRneiIs!!!not-base64!!!",
"signatures": [
{
"keyid": "SAMPLE-KEY-b7d0700f49640ccd",
"sig": "U0FNUExFIFNJR05BVFVSRSAtIE5PVCBBIFJFQUwgU0lHTkFUVVJFLCBWRVJJRklDQVRJT04gTVVTVCBGQUlMIFtkc3NlXQ=="
}
]
}
Specifications
- Seed
- 51200
- Sample Only
- true
- Format
- DSSE
- Damage
- payload is not valid base64
- Intentionally Corrupt
- true
- Well Formed Json
- true
- Line Endings
- LF
Testing contract
Expected to fail- Scenario
- Handle an attestation whose envelope is well-formed but whose payload is not.
- Expected result
- Verifier reports a payload-decode failure rather than treating the attestation as unverified-but-present, and never reports it as trusted.
What is a .json file?
JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.
How to use this file
Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.
How to use this file for testing
“DSSE Envelope With Undecodable Payload — Intentionally Corrupt” is a deterministic Novus Examples fixture for Error handling, JSON parsing. Deliberately corrupt and invalid files, clearly labelled, for testing how your tool fails.
Documented properties for this file: seed 51200 · damage: payload is not valid base64 · LF · intentionally corrupt. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.
Code examples
import json
with open("dsse-envelope-bad-payload.json") as f:
data = json.load(f)
print(type(data), len(data))Related files
- jsonRekor Transparency-Log EntryA transparency-log entry keyed by its own UUID at the top level — a shape that breaks parsers expecting a fixed root key — with a base64 body that decodes to a dsse record. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.

- jsonCycloneDX 1.6 Minimal SBOM (One Component)The smallest CycloneDX document that is still valid: required metadata, one fictional component, and no dependencies array — for testing that a reader handles an SBOM with nothing optional present. Every package, version, hash and licence is fictional — the tree describes nothing real.

- jsonCycloneDX SBOM With Schema Violations — Intentionally InvalidAn intentionally invalid CycloneDX SBOM: the JSON parses, but bomFormat is missing, one component has no name, and a dependency references a bom-ref that no component declares. Every package, version, hash and licence is fictional — the tree describes nothing real.

- jsonCycloneDX SBOM With Unicode Metadata (Edge Case)A CycloneDX SBOM whose author names and properties contain accented Latin, CJK, right-to-left Hebrew, emoji and a deliberately long property value — for testing encoding handling and field-width assumptions. Every package, version, hash and licence is fictional — the tree describes nothing real.

- jsonCycloneDX SBOM, Truncated — Intentionally CorruptAn intentionally corrupt CycloneDX SBOM: a valid 1.6 document cut off mid-object so the JSON never closes. Small on purpose — it exists to check that a reader fails cleanly instead of half-loading a component list. Every package, version, hash and licence is fictional — the tree describes nothing real.

- jsonDependency Alerts Feed (JSON)The shape a hosted dependency-alert API returns: alerts with lifecycle state, a nested advisory, a patched-version pointer and an explicitly null dismissed_reason on the alerts that were not dismissed. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.