Skip to content
Novus Examples
json1.2 KB

CycloneDX SBOM, Truncated — Intentionally Corrupt

An intentionally corrupt CycloneDX SBOM: a valid 1.6 document cut off mid-object so the JSON never closes. Small on purpose — it exists to check that a reader fails cleanly instead of half-loading a component list. Every package, version, hash and licence is fictional — the tree describes nothing real.

Preview — first 49 linesjson
{
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ef02ea57-bf4b-4d01-a155-9431c4783575",
  "version": 1,
  "metadata": {
    "timestamp": "2026-01-01T00:00:00Z",
    "tools": {
      "components": [
        {
          "type": "application",
          "name": "novus-sbom-fixture",
          "version": "1.0.0"
        }
      ]
    },
    "authors": [
      {
        "name": "Orchard SBOM Team (fictional)",
        "email": "sbom@orchard.example"
      }
    ],
    "component": {
      "type": "application",
      "bom-ref": "pkg:npm/%40orchard-example/gateway@4.2.0",
      "name": "@orchard-example/gateway",
      "version": "4.2.0",
      "purl": "pkg:npm/%40orchard-example/gateway@4.2.0",
      "licenses": [
        {
          "license": {
            "id": "Apache-2.0"
          }
        }
      ],
      "hashes": [
        {
          "alg": "SHA-256",
          "content": "cde01f0c8ff9d62ef958a3de288a2f1084db14bd47e1e10ff39a52412cca613f"
        }
      ],
      "supplier": {
        "name": "Example Softworks (fictional)",
        "url": [
          "https://sbom.orchard.example/supplier"
        ]
      },
      "external

Specifications

Seed
51200
Sample Only
true
Format
CycloneDX
Spec Version
1.6
Damage
truncated mid-object
Intentionally Corrupt
true
Line Endings
LF

Testing contract

Expected to fail
Scenario
Feed a truncated SBOM to a parser that streams rather than buffers.
Expected result
Parsing raises a clear unexpected-end-of-input error and no partial component list is committed to the caller.

What is a .json file?

JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.

How to use this file

Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.

How to use this file for testing

“CycloneDX SBOM, Truncated — Intentionally Corrupt” is a deterministic Novus Examples fixture for Error handling, JSON parsing. Deliberately corrupt and invalid files, clearly labelled, for testing how your tool fails.

Documented properties for this file: seed 51200 · damage: truncated mid-object · LF · intentionally corrupt. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.

Code examples

import json

with open("cyclonedx-1.6-truncated.json") as f:
    data = json.load(f)
print(type(data), len(data))

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.