Sigstore Bundle (v0.3 Shape)
A Sigstore bundle in the shape verifiers read: a SAMPLE certificate, a transparency-log entry with an inclusion proof and checkpoint, and the DSSE envelope carrying the provenance. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.
{
"mediaType": "application/vnd.dev.sigstore.bundle.v0.3+json",
"verificationMaterial": {
"certificate": {
"rawBytes": "U0FNUExFIENFUlRJRklDQVRFIC0gTk9UIEEgUkVBTCBYLjUwOSBDRVJUSUZJQ0FURQ=="
},
"tlogEntries": [
{
"logIndex": "51200",
"logId": {
"keyId": "XAgx+cTZqWgH2JTZ76Lu9ZqnbelAs18MGTCjvdp8Vb7hb3/NDef5LgYpcweq1rsP7tNdX8cP27wenlHn7cqhQQ=="
},
"kindVersion": {
"kind": "dsse",
"version": "0.0.1"
},
"integratedTime": "1767225600",
"inclusionPromise": {
"signedEntryTimestamp": "U0FNUExFIFNJR05BVFVSRSAtIE5PVCBBIFJFQUwgU0lHTkFUVVJFLCBWRVJJRklDQVRJT04gTVVTVCBGQUlMIFtzZXRd"
},
"inclusionProof": {
"logIndex": "51200",
"rootHash": "8d3orl27VbxDkHMdDPyTc6lyKLhQnk5sFnYD9ffeWNQ+LgXBr6eVhTWEgTLIxR4PEJiNtoLbBYbbgr/L7sM7pw==",
"treeSize": "51201",
"hashes": [
"Ygy3976bhlyZ5CHvkpQkLQeYnc9ufT/Wb9rYIBYMcKEc14PSYGKZeDgXC+SMArwxRfLbHMNcG6d0VVR4s7R/Cw==",
"eHjA2/3r8iTzOUrOQqVaDYkbLcHN4X8ffWaxRV4gmeeUYnKZMmFazjAAHvNC43SUtbJLQMY9KTBm0BsvO+J/cw=="
],
"checkpoint": {
"envelope": "sample-rekor.orchard.example - 51201\\nSAMPLE CHECKPOINT\\n"
}
}
}
]
},
"dsseEnvelope": {
"payloadType": "application/vnd.in-toto+json",
"payload": "eyJfdHlwZSI6Imh0dHBzOi8vaW4tdG90by5pby9TdGF0ZW1lbnQvdjEiLCJzdWJqZWN0IjpbeyJuYW1lIjoib3JjaGFyZC1nYXRld2F5LTQuMi4wLnRneiIsImRpZ2VzdCI6eyJzaGEyNTYiOiIwNmFmODhlMzE2Y2Y4ODllMGI3MjY0NWYyMzVmNzdjOTAwZDQ4OTcyNDU2YjFmZjZiYTRkZjQ5YWUyNGJlNzM0In19XSwicHJlZGljYXRlVHlwZSI6Imh0dHBzOi8vc2xzYS5kZXYvcHJvdmVuYW5jZS92MSIsInByZWRpY2F0ZSI6eyJidWlsZERlZmluaXRpb24iOnsiYnVpbGRUeXBlIjoiaHR0cHM6Ly9idWlsZC5vcmNoYXJkLmV4YW1wbGUvYnVpbGR0eXBlcy9ucG0vdjEiLCJleHRlcm5hbFBhcmFtZXRlcnMiOnsic291cmNlIjp7InVyaSI6ImdpdCtodHRwczovL2dpdC5vcmNoYXJkLmV4YW1wbGUvb3JjaGFyZC9nYXRld2F5QHJlZnMvdGFncy92NC4yLjAiLCJkaWdlc3QiOnsiZ2l0Q29tbWl0IjoiOTAyZWE4MTBmYmRkOGZmNzMwODJiZDI4NzM1ODU3MDlmMmNhNTAwYiJ9fSwiY29uZmlnIjp7ImVudHJ5UG9pbnQiOiIub3JjaGFyZC9idWlsZC55YW1sIiwidGFyZ2V0IjoicmVsZWFzZSJ9fSwiaW50ZXJuYWxQYXJhbWV0ZXJzIjp7InJ1bm5lckltYWdlIjoiZXhhbXBsZS1saW51eDozLjIwIiwiY2FjaGVFbmFibGVkIjpmYWxzZX0sInJlc29sdmVkRGVwZW5kZW5jaWVzIjpbeyJ1cmkiOiJnaXQraHR0cHM6Ly9naXQub3JjaGFyZC5leGFtcGxlL29yY2hhcmQvZ2F0ZXdheUByZWZzL3RhZ3MvdjQuMi4wIiwiZGlnZXN0Ijp7ImdpdENvbW1pdCI6IjkwMmVhODEwZmJkZDhmZjczMDgyYmQyODczNTg1NzA5ZjJjYTUwMGIifX0seyJ1cmkiOiJodHRwczovL3JlZ2lzdHJ5Lm9yY2hhcmQuZXhhbXBsZS9Ab3JjaGFyZC1leGFtcGxlL3JvdXRlci8tL3JvdXRlci0yLjEuMy50Z3oiLCJkaWdlc3QiOnsic2hhMjU2IjoiZDE3ZjBhNTE3MWEwMThjNDFjZGFhYTI3MDFiNmMzMmJmNDlmNzQwNDAzMmZhNDVlNTcyMWUyYjc5NGNkMmU1MSJ9fSx7InVyaSI6Imh0dHBzOi8vcmVnaXN0cnkub3JjaGFyZC5leGFtcGxlL2V4YW1wbGUtbG9nZ2VyLy0vZXhhbXBsZS1sb2dnZXItMy40LjEudGd6IiwiZGlnZXN0Ijp7InNoYTI1NiI6IjdmYjcyZWE1ODk4N2U1MzI3MjU5YjY2Mzg0Zjk2ZjVlNjU3YzNjZTUyMjViODg5MWM1NjdjYWM2YjU4NDMwZWMifX1dfSwicnVuRGV0YWlscyI6eyJidWlsZGVyIjp7ImlkIjoiaHR0cHM6Ly9idWlsZC5vcmNoYXJkLmV4YW1wbGUvYnVpbGRlcnMvaG9zdGVkL3YxIiwidmVyc2lvbiI6eyJvcmNoYXJkLWJ1aWxkZXIiOiIxLjQuMCJ9fSwibWV0YWRhdGEiOnsiaW52b2NhdGlvbklkIjoiaHR0cHM6Ly9idWlsZC5vcmNoYXJkLmV4YW1wbGUvcnVucy84ODE0Iiwic3RhcnRlZE9uIjoiMjAyNi0wMS0wMVQwMDowMDowMFoiLCJmaW5pc2hlZE9uIjoiMjAyNi0wMS0wMVQwMDowNjoxMloifSwiYnlwcm9kdWN0cyI6W3sibmFtZSI6ImJ1aWxkLmxvZyIsImRpZ2VzdCI6eyJzaGEyNTYiOiJlMDEyY2Q5ZWVjYTdjNTNlMTZjODlkOTgwNjg0NWQ4MzdmZWExNDQwZDk3M2RmODJlYjBjZDE3YjNhZDVhMWQwIn19XX19LCJub3Z1c19zYW1wbGVfbm90ZSI6IlNBTVBMRSDigJQgZmljdGlvbmFsIHN1cHBseS1jaGFpbiBkYXRhLiBFdmVyeSBwYWNrYWdlLCByZWdpc3RyeSwgdmVyc2lvbiwgaGFzaCwgbGljZW5jZSwgYWR2aXNvcnkgaWRlbnRpZmllciBhbmQgc2lnbmF0dXJlIGluIHRoaXMgZG9jdW1lbnQgaXMgaW52ZW50ZWQuIn0=",
"signatures": [
{
"keyid": "SAMPLE-KEY-b7d0700f49640ccd",
"sig": "U0FNUExFIFNJR05BVFVSRSAtIE5PVCBBIFJFQUwgU0lHTkFUVVJFLCBWRVJJRklDQVRJT04gTVVTVCBGQUlMIFtkc3NlXQ=="
}
]
},
"novus_sample_note": "Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real."
}
Specifications
- Seed
- 51200
- Sample Only
- true
- Format
- Sigstore bundle
- Media Type
- v0.3+json
- Tlog Entries
- 1
- Inclusion Proof Hashes
- 2
- Line Endings
- LF
Testing contract
Expected to pass- Scenario
- Parse a Sigstore bundle and locate its transparency-log inclusion proof.
- Expected result
- Reader finds one tlog entry of kind dsse with a two-hash inclusion proof and reports verification failure because the certificate is a SAMPLE placeholder.
What is a .json file?
JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.
How to use this file
Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.
How to use this file for testing
“Sigstore Bundle (v0.3 Shape)” is a deterministic Novus Examples fixture for JSON parsing, Certificate & key testing, Schema validation. Flat, deeply nested, JSON Lines, and intentionally invalid JSON for testing parsers and error handling.
Documented properties for this file: seed 51200 · LF · Sigstore bundle. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.
Feed the file to your parser and assert it handles the documented quirks — quoted delimiters, embedded newlines, ragged rows, or invalid syntax; the valid↔invalid distinction is labelled in the title.
Code examples
import json
with open("sigstore-bundle.json") as f:
data = json.load(f)
print(type(data), len(data))Related files
- jsonAttestation With a Full SPDX PredicateAn in-toto statement whose predicate is an entire SPDX 2.3 document — the nesting that makes attestation payloads large and that a size-limited verifier has to cope with. Every package, version, hash and licence is fictional — the tree describes nothing real.

- jsonBuild Metadata Manifest (JSON)The plain build record a CI job writes next to its artifacts — source ref and commit, builder identity, timings, toolchain versions and output digests — from which a provenance statement can be generated. Every package, version, hash and licence is fictional — the tree describes nothing real.

- jsonDSSE Envelope Wrapping a Provenance StatementA DSSE envelope whose base64 payload decodes to the SLSA v1 statement in this family — the wrapper attestation tooling actually transports. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.

- jsonin-toto Layout (Supply-Chain Policy)The policy half of in-toto: a layout declaring which steps must run, which keys may sign them, and the MATCH/CREATE/DISALLOW artifact rules that bind each step's products to the next step's materials. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.

- jsonin-toto Link MetadataAn in-toto link file recording one build step: the materials that went in, the products that came out and their sha256 digests, wrapped in the signed/signatures envelope in-toto uses. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.

- jsonin-toto Statement With SLSA Provenance v0.2The predecessor predicate: SLSA v0.2 uses invocation/materials/buildConfig where v1 uses buildDefinition/runDetails, so this file is the migration test for any verifier that must accept both. Every package, version, hash and licence is fictional — the tree describes nothing real.

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.