Reproducible Build Comparison Report
Two independent builds of the same fictional artifact on different architectures, both producing one digest — the evidence a rebuilder publishes, with SOURCE_DATE_EPOCH recorded as the thing that made it possible. Every package, version, hash and licence is fictional — the tree describes nothing real.
{
"schema": "novus-sample/reproducible-build/1",
"artifact": {
"name": "orchard-gateway-4.2.0.tgz",
"sha256": "06af88e316cf889e0b72645f235f77c900d48972456b1ff6ba4df49ae24be734"
},
"builds": [
{
"builder": "https://build.orchard.example/builders/hosted/v1",
"runId": "8814",
"startedOn": "2026-01-01T00:00:00Z",
"sha256": "06af88e316cf889e0b72645f235f77c900d48972456b1ff6ba4df49ae24be734",
"environment": {
"os": "example-linux 3.20",
"arch": "x86_64",
"tz": "UTC",
"sourceDateEpoch": 1767225600
}
},
{
"builder": "https://build.orchard.example/builders/rebuilder/v1",
"runId": "8815",
"startedOn": "2026-01-02T00:00:00Z",
"sha256": "06af88e316cf889e0b72645f235f77c900d48972456b1ff6ba4df49ae24be734",
"environment": {
"os": "example-linux 3.20",
"arch": "aarch64",
"tz": "UTC",
"sourceDateEpoch": 1767225600
}
}
],
"reproducible": true,
"differences": [],
"novus_sample_note": "SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented."
}
Specifications
- Seed
- 51200
- Sample Only
- true
- Builds
- 2
- Reproducible
- true
- Differences
- 0
- Source Date Epoch
- 1767225600
- Line Endings
- LF
Testing contract
Expected to pass- Scenario
- Compare independent rebuild results and decide whether a build is reproducible.
- Expected result
- Both build records carry the same sha256, the differences array is empty, and flipping either digest must make reproducible evaluate false.
What is a .json file?
JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.
How to use this file
Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.
How to use this file for testing
“Reproducible Build Comparison Report” is a deterministic Novus Examples fixture for JSON parsing, Visual diff / regression, Schema validation. Flat, deeply nested, JSON Lines, and intentionally invalid JSON for testing parsers and error handling.
Documented properties for this file: seed 51200 · LF. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.
Feed the file to your parser and assert it handles the documented quirks — quoted delimiters, embedded newlines, ragged rows, or invalid syntax; the valid↔invalid distinction is labelled in the title.
Code examples
import json
with open("reproducible-build-report.json") as f:
data = json.load(f)
print(type(data), len(data))Related files
- jsonRekor Transparency-Log EntryA transparency-log entry keyed by its own UUID at the top level — a shape that breaks parsers expecting a fixed root key — with a base64 body that decodes to a dsse record. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.

- jsonSBOM Attestation Envelope (cosign Shape)An attestation that binds an SBOM to an artifact digest rather than shipping the SBOM loose — the pattern keyless signing produces, complete with the empty keyid that identity-based signing leaves behind. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.

- jsonSigstore Bundle (v0.3 Shape)A Sigstore bundle in the shape verifiers read: a SAMPLE certificate, a transparency-log entry with an inclusion proof and checkpoint, and the DSSE envelope carrying the provenance. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.

- jsoncargo-audit Report (JSON)A cargo-audit report that shows three findings while a fourth is on the ignore list, plus an unmaintained-crate warning — so a gate must decide whether warnings count against it. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

- jsonCSAF 2.0 VEX DocumentA CSAF 2.0 VEX advisory with the nested product tree that CSAF requires — vendor, product name, product version — and product_status buckets rather than a per-statement status field. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

- jsonCycloneDX 1.5 Application SBOM (JSON)A CycloneDX 1.5 SBOM of the same fictional tree, useful for spec-version migration tests: 1.5 introduced the object form of metadata.tools and this file uses it, while dropping the 1.6-only external references. Every package, version, hash and licence is fictional — the tree describes nothing real.

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.