Skip to content
Novus Examples
json4 KB

Sigstore Bundle (v0.3 Shape)

A Sigstore bundle in the shape verifiers read: a SAMPLE certificate, a transparency-log entry with an inclusion proof and checkpoint, and the DSSE envelope carrying the provenance. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.

Preview — first 48 linesjson
{
  "mediaType": "application/vnd.dev.sigstore.bundle.v0.3+json",
  "verificationMaterial": {
    "certificate": {
      "rawBytes": "U0FNUExFIENFUlRJRklDQVRFIC0gTk9UIEEgUkVBTCBYLjUwOSBDRVJUSUZJQ0FURQ=="
    },
    "tlogEntries": [
      {
        "logIndex": "51200",
        "logId": {
          "keyId": "XAgx+cTZqWgH2JTZ76Lu9ZqnbelAs18MGTCjvdp8Vb7hb3/NDef5LgYpcweq1rsP7tNdX8cP27wenlHn7cqhQQ=="
        },
        "kindVersion": {
          "kind": "dsse",
          "version": "0.0.1"
        },
        "integratedTime": "1767225600",
        "inclusionPromise": {
          "signedEntryTimestamp": "U0FNUExFIFNJR05BVFVSRSAtIE5PVCBBIFJFQUwgU0lHTkFUVVJFLCBWRVJJRklDQVRJT04gTVVTVCBGQUlMIFtzZXRd"
        },
        "inclusionProof": {
          "logIndex": "51200",
          "rootHash": "8d3orl27VbxDkHMdDPyTc6lyKLhQnk5sFnYD9ffeWNQ+LgXBr6eVhTWEgTLIxR4PEJiNtoLbBYbbgr/L7sM7pw==",
          "treeSize": "51201",
          "hashes": [
            "Ygy3976bhlyZ5CHvkpQkLQeYnc9ufT/Wb9rYIBYMcKEc14PSYGKZeDgXC+SMArwxRfLbHMNcG6d0VVR4s7R/Cw==",
            "eHjA2/3r8iTzOUrOQqVaDYkbLcHN4X8ffWaxRV4gmeeUYnKZMmFazjAAHvNC43SUtbJLQMY9KTBm0BsvO+J/cw=="
          ],
          "checkpoint": {
            "envelope": "sample-rekor.orchard.example - 51201\\nSAMPLE CHECKPOINT\\n"
          }
        }
      }
    ]
  },
  "dsseEnvelope": {
    "payloadType": "application/vnd.in-toto+json",
    "payload": "eyJfdHlwZSI6Imh0dHBzOi8vaW4tdG90by5pby9TdGF0ZW1lbnQvdjEiLCJzdWJqZWN0IjpbeyJuYW1lIjoib3JjaGFyZC1nYXRld2F5LTQuMi4wLnRneiIsImRpZ2VzdCI6eyJzaGEyNTYiOiIwNmFmODhlMzE2Y2Y4ODllMGI3MjY0NWYyMzVmNzdjOTAwZDQ4OTcyNDU2YjFmZjZiYTRkZjQ5YWUyNGJlNzM0In19XSwicHJlZGljYXRlVHlwZSI6Imh0dHBzOi8vc2xzYS5kZXYvcHJvdmVuYW5jZS92MSIsInByZWRpY2F0ZSI6eyJidWlsZERlZmluaXRpb24iOnsiYnVpbGRUeXBlIjoiaHR0cHM6Ly9idWlsZC5vcmNoYXJkLmV4YW1wbGUvYnVpbGR0eXBlcy9ucG0vdjEiLCJleHRlcm5hbFBhcmFtZXRlcnMiOnsic291cmNlIjp7InVyaSI6ImdpdCtodHRwczovL2dpdC5vcmNoYXJkLmV4YW1wbGUvb3JjaGFyZC9nYXRld2F5QHJlZnMvdGFncy92NC4yLjAiLCJkaWdlc3QiOnsiZ2l0Q29tbWl0IjoiOTAyZWE4MTBmYmRkOGZmNzMwODJiZDI4NzM1ODU3MDlmMmNhNTAwYiJ9fSwiY29uZmlnIjp7ImVudHJ5UG9pbnQiOiIub3JjaGFyZC9idWlsZC55YW1sIiwidGFyZ2V0IjoicmVsZWFzZSJ9fSwiaW50ZXJuYWxQYXJhbWV0ZXJzIjp7InJ1bm5lckltYWdlIjoiZXhhbXBsZS1saW51eDozLjIwIiwiY2FjaGVFbmFibGVkIjpmYWxzZX0sInJlc29sdmVkRGVwZW5kZW5jaWVzIjpbeyJ1cmkiOiJnaXQraHR0cHM6Ly9naXQub3JjaGFyZC5leGFtcGxlL29yY2hhcmQvZ2F0ZXdheUByZWZzL3RhZ3MvdjQuMi4wIiwiZGlnZXN0Ijp7ImdpdENvbW1pdCI6IjkwMmVhODEwZmJkZDhmZjczMDgyYmQyODczNTg1NzA5ZjJjYTUwMGIifX0seyJ1cmkiOiJodHRwczovL3JlZ2lzdHJ5Lm9yY2hhcmQuZXhhbXBsZS9Ab3JjaGFyZC1leGFtcGxlL3JvdXRlci8tL3JvdXRlci0yLjEuMy50Z3oiLCJkaWdlc3QiOnsic2hhMjU2IjoiZDE3ZjBhNTE3MWEwMThjNDFjZGFhYTI3MDFiNmMzMmJmNDlmNzQwNDAzMmZhNDVlNTcyMWUyYjc5NGNkMmU1MSJ9fSx7InVyaSI6Imh0dHBzOi8vcmVnaXN0cnkub3JjaGFyZC5leGFtcGxlL2V4YW1wbGUtbG9nZ2VyLy0vZXhhbXBsZS1sb2dnZXItMy40LjEudGd6IiwiZGlnZXN0Ijp7InNoYTI1NiI6IjdmYjcyZWE1ODk4N2U1MzI3MjU5YjY2Mzg0Zjk2ZjVlNjU3YzNjZTUyMjViODg5MWM1NjdjYWM2YjU4NDMwZWMifX1dfSwicnVuRGV0YWlscyI6eyJidWlsZGVyIjp7ImlkIjoiaHR0cHM6Ly9idWlsZC5vcmNoYXJkLmV4YW1wbGUvYnVpbGRlcnMvaG9zdGVkL3YxIiwidmVyc2lvbiI6eyJvcmNoYXJkLWJ1aWxkZXIiOiIxLjQuMCJ9fSwibWV0YWRhdGEiOnsiaW52b2NhdGlvbklkIjoiaHR0cHM6Ly9idWlsZC5vcmNoYXJkLmV4YW1wbGUvcnVucy84ODE0Iiwic3RhcnRlZE9uIjoiMjAyNi0wMS0wMVQwMDowMDowMFoiLCJmaW5pc2hlZE9uIjoiMjAyNi0wMS0wMVQwMDowNjoxMloifSwiYnlwcm9kdWN0cyI6W3sibmFtZSI6ImJ1aWxkLmxvZyIsImRpZ2VzdCI6eyJzaGEyNTYiOiJlMDEyY2Q5ZWVjYTdjNTNlMTZjODlkOTgwNjg0NWQ4MzdmZWExNDQwZDk3M2RmODJlYjBjZDE3YjNhZDVhMWQwIn19XX19LCJub3Z1c19zYW1wbGVfbm90ZSI6IlNBTVBMRSDigJQgZmljdGlvbmFsIHN1cHBseS1jaGFpbiBkYXRhLiBFdmVyeSBwYWNrYWdlLCByZWdpc3RyeSwgdmVyc2lvbiwgaGFzaCwgbGljZW5jZSwgYWR2aXNvcnkgaWRlbnRpZmllciBhbmQgc2lnbmF0dXJlIGluIHRoaXMgZG9jdW1lbnQgaXMgaW52ZW50ZWQuIn0=",
    "signatures": [
      {
        "keyid": "SAMPLE-KEY-b7d0700f49640ccd",
        "sig": "U0FNUExFIFNJR05BVFVSRSAtIE5PVCBBIFJFQUwgU0lHTkFUVVJFLCBWRVJJRklDQVRJT04gTVVTVCBGQUlMIFtkc3NlXQ=="
      }
    ]
  },
  "novus_sample_note": "Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real."
}

Specifications

Seed
51200
Sample Only
true
Format
Sigstore bundle
Media Type
v0.3+json
Tlog Entries
1
Inclusion Proof Hashes
2
Line Endings
LF

Testing contract

Expected to pass
Scenario
Parse a Sigstore bundle and locate its transparency-log inclusion proof.
Expected result
Reader finds one tlog entry of kind dsse with a two-hash inclusion proof and reports verification failure because the certificate is a SAMPLE placeholder.

What is a .json file?

JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.

How to use this file

Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.

How to use this file for testing

“Sigstore Bundle (v0.3 Shape)” is a deterministic Novus Examples fixture for JSON parsing, Certificate & key testing, Schema validation. Flat, deeply nested, JSON Lines, and intentionally invalid JSON for testing parsers and error handling.

Documented properties for this file: seed 51200 · LF · Sigstore bundle. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.

Feed the file to your parser and assert it handles the documented quirks — quoted delimiters, embedded newlines, ragged rows, or invalid syntax; the valid↔invalid distinction is labelled in the title.

Code examples

import json

with open("sigstore-bundle.json") as f:
    data = json.load(f)
print(type(data), len(data))

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.