Release SHA256SUMS Manifest
The oldest supply-chain artifact there is: a sha256sum manifest with the exact two-space separator the tool emits, listing a fictional release tarball and its nine dependency archives. Every package, version, hash and licence is fictional — the tree describes nothing real.
# SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented.
06af88e316cf889e0b72645f235f77c900d48972456b1ff6ba4df49ae24be734 orchard-gateway-4.2.0.tgz
d17f0a5171a018c41cdaaa2701b6c32bf49f7404032fa45e5721e2b794cd2e51 router-2.1.3.tgz
05dc223ec1875dfd80d8c5873f8c29f036f98587f2fe2d02abc7c718bfb4b8bf http-core-1.8.0.tgz
4a8930c617fd12bb99d26e868224d9918e4a3e00f8dd26b876ed19eb6e664f73 example-metrics-4.0.0.tgz
f7af2ad2d3c3daaa5991b0eae38ffa151a2e2f3bf0f2bdd7333adc3a1dc860f7 example-cache-0.9.2.tgz
25b4571f3faedb8df3979d9e509e331b6b88503d8d0057e6414e936e084a56cb example-crypto-shim-1.2.0.tgz
7fb72ea58987e5327259b66384f96f5e657c3ce5225b8891c567cac6b58430ec example-logger-3.4.1.tgz
4f2a78f8fb4883a2efd6b73b447f632599790c08e25bb7184f501b5f2b9af33f example-retry-1.0.4.tgz
74e30e4812a0cc92bd7c1a965e6f953f5d92b9eaf3cd77d90663a7344e939b63 example-json-path-2.0.5.tgz
d7094de3c8e15621381e5f9f02c0eecb9977d249a8a06ab2b0a34f5344a039af example-yaml-lite-1.1.7.tgz
Specifications
- Seed
- 51200
- Sample Only
- true
- Format
- sha256sum output
- Entries
- 10
- Separator
- two spaces
- Line Endings
- LF
Testing contract
Expected to pass- Scenario
- Parse sha256sum output, where the separator is two spaces and not a tab.
- Expected result
- Ten entries split into a 64-character hex digest and a filename, and the release tarball's digest matches the provenance statement's subject.
What is a .txt file?
TXT is a plain-text file containing unformatted character data with no styling or structure beyond line breaks. Its interpretation depends on character encoding, most commonly UTF-8, and on line-ending convention. It is the most universal and portable text container.
How to use this file
Use an example TXT to test encoding detection, line-ending (LF versus CRLF) handling, and any tool that reads or streams raw text input.
How to use this file for testing
“Release SHA256SUMS Manifest” is a deterministic Novus Examples fixture for Config parsing, Conversion testing, Error handling. TOML and INI configuration files with nested sections and typed values — for testing config parsers and loaders.
Documented properties for this file: seed 51200 · 10 entries · LF. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.
Point your config loader at the file and assert it reads the documented sections and typed values, including any deliberately-tricky nesting or comments.
Related files
- lockGemfile.lock (Bundler)A Bundler lockfile in its indentation-significant block format — specs nested under GEM, transitive requirements nested one level deeper, and the BUNDLED WITH version on its own indented line. Every package, version, hash and licence is fictional — the tree describes nothing real.

- txtgo.sum Checksum Lines (as .txt)go.sum content: two h1: lines per fictional module — one for the module zip and one for its go.mod — which is the pairing a verifier must require. Served as .txt because go.sum has no registered media type. Every package, version, hash and licence is fictional — the tree describes nothing real.

- lockmix.lock (Elixir)An Elixir mix.lock: a literal Elixir map whose values are tuples of atoms, strings and lists. It is neither JSON nor TOML, so a generic lockfile reader has to special-case it. Every package, version, hash and licence is fictional — the tree describes nothing real.

- lockyarn.lock (Berry, __metadata version 8)A modern Yarn Berry lockfile: YAML-shaped with an __metadata header, npm: protocol resolutions and cache-key-prefixed checksums — deliberately different from the Classic file in the same family. Every package, version, hash and licence is fictional — the tree describes nothing real.

- txtDetached Signature, ASCII Armor — SAMPLE ShapeAn ASCII-armored detached signature block of the shape that accompanies a SHA256SUMS file. It is a SAMPLE placeholder, not a valid OpenPGP signature — armor detectors will find it, verifiers must reject it. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.

- lockbun.lock (Text Lockfile)Bun's text lockfile, where each package is a positional array of descriptor, dependency map and integrity string rather than an object — a shape that breaks parsers assuming every lock entry is keyed. Every package, version, hash and licence is fictional — the tree describes nothing real.

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.