DSSE Envelope Wrapping a Provenance Statement
A DSSE envelope whose base64 payload decodes to the SLSA v1 statement in this family — the wrapper attestation tooling actually transports. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.
{
"payloadType": "application/vnd.in-toto+json",
"payload": "eyJfdHlwZSI6Imh0dHBzOi8vaW4tdG90by5pby9TdGF0ZW1lbnQvdjEiLCJzdWJqZWN0IjpbeyJuYW1lIjoib3JjaGFyZC1nYXRld2F5LTQuMi4wLnRneiIsImRpZ2VzdCI6eyJzaGEyNTYiOiIwNmFmODhlMzE2Y2Y4ODllMGI3MjY0NWYyMzVmNzdjOTAwZDQ4OTcyNDU2YjFmZjZiYTRkZjQ5YWUyNGJlNzM0In19XSwicHJlZGljYXRlVHlwZSI6Imh0dHBzOi8vc2xzYS5kZXYvcHJvdmVuYW5jZS92MSIsInByZWRpY2F0ZSI6eyJidWlsZERlZmluaXRpb24iOnsiYnVpbGRUeXBlIjoiaHR0cHM6Ly9idWlsZC5vcmNoYXJkLmV4YW1wbGUvYnVpbGR0eXBlcy9ucG0vdjEiLCJleHRlcm5hbFBhcmFtZXRlcnMiOnsic291cmNlIjp7InVyaSI6ImdpdCtodHRwczovL2dpdC5vcmNoYXJkLmV4YW1wbGUvb3JjaGFyZC9nYXRld2F5QHJlZnMvdGFncy92NC4yLjAiLCJkaWdlc3QiOnsiZ2l0Q29tbWl0IjoiOTAyZWE4MTBmYmRkOGZmNzMwODJiZDI4NzM1ODU3MDlmMmNhNTAwYiJ9fSwiY29uZmlnIjp7ImVudHJ5UG9pbnQiOiIub3JjaGFyZC9idWlsZC55YW1sIiwidGFyZ2V0IjoicmVsZWFzZSJ9fSwiaW50ZXJuYWxQYXJhbWV0ZXJzIjp7InJ1bm5lckltYWdlIjoiZXhhbXBsZS1saW51eDozLjIwIiwiY2FjaGVFbmFibGVkIjpmYWxzZX0sInJlc29sdmVkRGVwZW5kZW5jaWVzIjpbeyJ1cmkiOiJnaXQraHR0cHM6Ly9naXQub3JjaGFyZC5leGFtcGxlL29yY2hhcmQvZ2F0ZXdheUByZWZzL3RhZ3MvdjQuMi4wIiwiZGlnZXN0Ijp7ImdpdENvbW1pdCI6IjkwMmVhODEwZmJkZDhmZjczMDgyYmQyODczNTg1NzA5ZjJjYTUwMGIifX0seyJ1cmkiOiJodHRwczovL3JlZ2lzdHJ5Lm9yY2hhcmQuZXhhbXBsZS9Ab3JjaGFyZC1leGFtcGxlL3JvdXRlci8tL3JvdXRlci0yLjEuMy50Z3oiLCJkaWdlc3QiOnsic2hhMjU2IjoiZDE3ZjBhNTE3MWEwMThjNDFjZGFhYTI3MDFiNmMzMmJmNDlmNzQwNDAzMmZhNDVlNTcyMWUyYjc5NGNkMmU1MSJ9fSx7InVyaSI6Imh0dHBzOi8vcmVnaXN0cnkub3JjaGFyZC5leGFtcGxlL2V4YW1wbGUtbG9nZ2VyLy0vZXhhbXBsZS1sb2dnZXItMy40LjEudGd6IiwiZGlnZXN0Ijp7InNoYTI1NiI6IjdmYjcyZWE1ODk4N2U1MzI3MjU5YjY2Mzg0Zjk2ZjVlNjU3YzNjZTUyMjViODg5MWM1NjdjYWM2YjU4NDMwZWMifX1dfSwicnVuRGV0YWlscyI6eyJidWlsZGVyIjp7ImlkIjoiaHR0cHM6Ly9idWlsZC5vcmNoYXJkLmV4YW1wbGUvYnVpbGRlcnMvaG9zdGVkL3YxIiwidmVyc2lvbiI6eyJvcmNoYXJkLWJ1aWxkZXIiOiIxLjQuMCJ9fSwibWV0YWRhdGEiOnsiaW52b2NhdGlvbklkIjoiaHR0cHM6Ly9idWlsZC5vcmNoYXJkLmV4YW1wbGUvcnVucy84ODE0Iiwic3RhcnRlZE9uIjoiMjAyNi0wMS0wMVQwMDowMDowMFoiLCJmaW5pc2hlZE9uIjoiMjAyNi0wMS0wMVQwMDowNjoxMloifSwiYnlwcm9kdWN0cyI6W3sibmFtZSI6ImJ1aWxkLmxvZyIsImRpZ2VzdCI6eyJzaGEyNTYiOiJlMDEyY2Q5ZWVjYTdjNTNlMTZjODlkOTgwNjg0NWQ4MzdmZWExNDQwZDk3M2RmODJlYjBjZDE3YjNhZDVhMWQwIn19XX19LCJub3Z1c19zYW1wbGVfbm90ZSI6IlNBTVBMRSDigJQgZmljdGlvbmFsIHN1cHBseS1jaGFpbiBkYXRhLiBFdmVyeSBwYWNrYWdlLCByZWdpc3RyeSwgdmVyc2lvbiwgaGFzaCwgbGljZW5jZSwgYWR2aXNvcnkgaWRlbnRpZmllciBhbmQgc2lnbmF0dXJlIGluIHRoaXMgZG9jdW1lbnQgaXMgaW52ZW50ZWQuIn0=",
"signatures": [
{
"keyid": "SAMPLE-KEY-b7d0700f49640ccd",
"sig": "U0FNUExFIFNJR05BVFVSRSAtIE5PVCBBIFJFQUwgU0lHTkFUVVJFLCBWRVJJRklDQVRJT04gTVVTVCBGQUlMIFtkc3NlXQ=="
}
]
}
Specifications
- Seed
- 51200
- Sample Only
- true
- Format
- DSSE
- Payload Type
- application/vnd.in-toto+json
- Payload Encoding
- base64
- Signatures
- 1
- Line Endings
- LF
Testing contract
Expected to pass- Scenario
- Decode a DSSE payload and verify it against the enclosed statement.
- Expected result
- Base64 decoding yields byte-identical JSON to the unsigned statement file, and signature verification fails because the sig is a SAMPLE placeholder.
What is a .json file?
JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.
How to use this file
Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.
How to use this file for testing
“DSSE Envelope Wrapping a Provenance Statement” is a deterministic Novus Examples fixture for JSON parsing, JWT / JWKS testing, Schema validation. Flat, deeply nested, JSON Lines, and intentionally invalid JSON for testing parsers and error handling.
Documented properties for this file: seed 51200 · LF · DSSE. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.
Feed the file to your parser and assert it handles the documented quirks — quoted delimiters, embedded newlines, ragged rows, or invalid syntax; the valid↔invalid distinction is labelled in the title.
Code examples
import json
with open("dsse-envelope.json") as f:
data = json.load(f)
print(type(data), len(data))Related files
- jsonRekor Transparency-Log EntryA transparency-log entry keyed by its own UUID at the top level — a shape that breaks parsers expecting a fixed root key — with a base64 body that decodes to a dsse record. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.

- jsonSBOM Attestation Envelope (cosign Shape)An attestation that binds an SBOM to an artifact digest rather than shipping the SBOM loose — the pattern keyless signing produces, complete with the empty keyid that identity-based signing leaves behind. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.

- jsonSigstore Bundle (v0.3 Shape)A Sigstore bundle in the shape verifiers read: a SAMPLE certificate, a transparency-log entry with an inclusion proof and checkpoint, and the DSSE envelope carrying the provenance. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.

- jsoncargo-audit Report (JSON)A cargo-audit report that shows three findings while a fourth is on the ignore list, plus an unmaintained-crate warning — so a gate must decide whether warnings count against it. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

- jsonCSAF 2.0 VEX DocumentA CSAF 2.0 VEX advisory with the nested product tree that CSAF requires — vendor, product name, product version — and product_status buckets rather than a per-statement status field. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

- jsonCycloneDX 1.5 Application SBOM (JSON)A CycloneDX 1.5 SBOM of the same fictional tree, useful for spec-version migration tests: 1.5 introduced the object form of metadata.tools and this file uses it, while dropping the 1.6-only external references. Every package, version, hash and licence is fictional — the tree describes nothing real.

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.