Skip to content
Novus Examples
json11.3 KB

CycloneDX SBOM With Schema Violations — Intentionally Invalid

An intentionally invalid CycloneDX SBOM: the JSON parses, but bomFormat is missing, one component has no name, and a dependency references a bom-ref that no component declares. Every package, version, hash and licence is fictional — the tree describes nothing real.

Preview — first 50 linesjson
{
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5c9d883f-56b3-4f89-a620-aa94a4791a3c",
  "version": 1,
  "metadata": {
    "timestamp": "2026-01-01T00:00:00Z",
    "tools": {
      "components": [
        {
          "type": "application",
          "name": "novus-sbom-fixture",
          "version": "1.0.0"
        }
      ]
    },
    "authors": [
      {
        "name": "Orchard SBOM Team (fictional)",
        "email": "sbom@orchard.example"
      }
    ],
    "component": {
      "type": "application",
      "bom-ref": "pkg:npm/%40orchard-example/gateway@4.2.0",
      "name": "@orchard-example/gateway",
      "version": "4.2.0",
      "purl": "pkg:npm/%40orchard-example/gateway@4.2.0",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "cde01f0c8ff9d62ef958a3de288a2f1084db14bd47e1e10ff39a52412cca613f"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "externalReferences": [
        {
          "type": "distribution",
          "url": "https://registry.orchard.example/@orchard-example/gateway/-/gateway-4.2.0.tgz"
455 lines total — download for the full file.

Specifications

Seed
51200
Sample Only
true
Format
CycloneDX
Spec Version
1.6
Violations
3
Intentionally Invalid
true
Well Formed Json
true
Line Endings
LF

Testing contract

Expected to fail
Scenario
Run a CycloneDX schema validator over a well-formed but non-conforming SBOM.
Expected result
Validator reports at least three distinct violations — absent bomFormat, component missing required name, dangling dependency ref — rather than accepting the file because the JSON parsed.

What is a .json file?

JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.

How to use this file

Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.

How to use this file for testing

“CycloneDX SBOM With Schema Violations — Intentionally Invalid” is a deterministic Novus Examples fixture for Schema validation, Error handling, JSON parsing. JSON Schema documents describing a data shape — for testing validators and schema-aware tooling.

Documented properties for this file: seed 51200 · LF · CycloneDX. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.

Code examples

import json

with open("cyclonedx-1.6-schema-violations.json") as f:
    data = json.load(f)
print(type(data), len(data))

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.