CycloneDX SBOM With Schema Violations — Intentionally Invalid
An intentionally invalid CycloneDX SBOM: the JSON parses, but bomFormat is missing, one component has no name, and a dependency references a bom-ref that no component declares. Every package, version, hash and licence is fictional — the tree describes nothing real.
{
"specVersion": "1.6",
"serialNumber": "urn:uuid:5c9d883f-56b3-4f89-a620-aa94a4791a3c",
"version": 1,
"metadata": {
"timestamp": "2026-01-01T00:00:00Z",
"tools": {
"components": [
{
"type": "application",
"name": "novus-sbom-fixture",
"version": "1.0.0"
}
]
},
"authors": [
{
"name": "Orchard SBOM Team (fictional)",
"email": "sbom@orchard.example"
}
],
"component": {
"type": "application",
"bom-ref": "pkg:npm/%40orchard-example/gateway@4.2.0",
"name": "@orchard-example/gateway",
"version": "4.2.0",
"purl": "pkg:npm/%40orchard-example/gateway@4.2.0",
"licenses": [
{
"license": {
"id": "Apache-2.0"
}
}
],
"hashes": [
{
"alg": "SHA-256",
"content": "cde01f0c8ff9d62ef958a3de288a2f1084db14bd47e1e10ff39a52412cca613f"
}
],
"supplier": {
"name": "Example Softworks (fictional)",
"url": [
"https://sbom.orchard.example/supplier"
]
},
"externalReferences": [
{
"type": "distribution",
"url": "https://registry.orchard.example/@orchard-example/gateway/-/gateway-4.2.0.tgz"Specifications
- Seed
- 51200
- Sample Only
- true
- Format
- CycloneDX
- Spec Version
- 1.6
- Violations
- 3
- Intentionally Invalid
- true
- Well Formed Json
- true
- Line Endings
- LF
Testing contract
Expected to fail- Scenario
- Run a CycloneDX schema validator over a well-formed but non-conforming SBOM.
- Expected result
- Validator reports at least three distinct violations — absent bomFormat, component missing required name, dangling dependency ref — rather than accepting the file because the JSON parsed.
What is a .json file?
JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.
How to use this file
Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.
How to use this file for testing
“CycloneDX SBOM With Schema Violations — Intentionally Invalid” is a deterministic Novus Examples fixture for Schema validation, Error handling, JSON parsing. JSON Schema documents describing a data shape — for testing validators and schema-aware tooling.
Documented properties for this file: seed 51200 · LF · CycloneDX. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.
Code examples
import json
with open("cyclonedx-1.6-schema-violations.json") as f:
data = json.load(f)
print(type(data), len(data))Related files
- jsonCycloneDX 1.6 Minimal SBOM (One Component)The smallest CycloneDX document that is still valid: required metadata, one fictional component, and no dependencies array — for testing that a reader handles an SBOM with nothing optional present. Every package, version, hash and licence is fictional — the tree describes nothing real.

- jsonnpm Lockfile With Integrity Mismatch — Intentionally InvalidAn intentionally invalid npm lockfile: two fictional packages carry sha512 integrity strings that cannot match their resolved tarballs — one derived from the wrong version, one a padded placeholder. Every package, version, hash and licence is fictional — the tree describes nothing real.

- jsonOSV Record With Schema Violations — Intentionally InvalidAn intentionally invalid OSV record: the JSON parses, but the required id is missing, modified is not an RFC 3339 timestamp, the SEMVER range has a fixed event with no introduced event, and severity.score is a number where the schema demands a CVSS vector string. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

- jsonRekor Transparency-Log EntryA transparency-log entry keyed by its own UUID at the top level — a shape that breaks parsers expecting a fixed root key — with a base64 body that decodes to a dsse record. Signatures, key ids and certificates here are SAMPLE placeholders — the base64 decodes to the words 'SAMPLE SIGNATURE', so verification must fail. Nothing here is cryptographically valid and no key material is real.

- jsonTrivy Clean Scan Report (Zero Findings)A clean scan report — the case dashboards get wrong. Trivy omits the Vulnerabilities key entirely rather than emitting an empty array, so a reader that assumes the key exists throws on a passing build. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

- jsonTrivy Container Image Scan Report (JSON)A Trivy-shaped image report with three result blocks — OS packages, language packages and a Dockerfile misconfiguration — so a parser must handle a Results array whose members have different keys. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.