Skip to content
Novus Examples
yaml9 KB

SPDX 2.3 Application SBOM (YAML)

The SPDX 2.3 SBOM in its YAML serialisation — the third form the specification defines alongside JSON and tag-value, and the one most often hand-edited in a repository. Every package, version, hash and licence is fictional — the tree describes nothing real.

Preview — first 50 linesyaml
# SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented.

spdxVersion: SPDX-2.3
dataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT
name: orchard-gateway-4.2.0
documentNamespace: "https://sbom.orchard.example/spdx/a199a062-0945-4011-a6cd-d5c4768f4e59"
creationInfo:
  created: "2026-01-01T00:00:00Z"
  creators:
    - "Organization: Example Softworks (fictional)"
    - "Tool: novus-sbom-fixture-1.0.0"
  licenseListVersion: 3.22
  comment: "SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented."
packages:
  - SPDXID: SPDXRef-Package-orchard-example-gateway
    name: "@orchard-example/gateway"
    versionInfo: 4.2.0
    downloadLocation: "https://registry.orchard.example/@orchard-example/gateway/-/gateway-4.2.0.tgz"
    filesAnalyzed: false
    supplier: "Organization: Example Softworks (fictional)"
    licenseConcluded: Apache-2.0
    licenseDeclared: Apache-2.0
    copyrightText: NOASSERTION
    checksums:
      - algorithm: SHA256
        checksumValue: cde01f0c8ff9d62ef958a3de288a2f1084db14bd47e1e10ff39a52412cca613f
    externalRefs:
      - referenceCategory: PACKAGE-MANAGER
        referenceType: purl
        referenceLocator: "pkg:npm/%40orchard-example/gateway@4.2.0"
  - SPDXID: SPDXRef-Package-orchard-example-router
    name: "@orchard-example/router"
    versionInfo: 2.1.3
    downloadLocation: "https://registry.orchard.example/@orchard-example/router/-/router-2.1.3.tgz"
    filesAnalyzed: false
    supplier: "Organization: Example Softworks (fictional)"
    licenseConcluded: Apache-2.0
    licenseDeclared: Apache-2.0
    copyrightText: NOASSERTION
    checksums:
      - algorithm: SHA256
        checksumValue: d17f0a5171a018c41cdaaa2701b6c32bf49f7404032fa45e5721e2b794cd2e51
    externalRefs:
      - referenceCategory: PACKAGE-MANAGER
        referenceType: purl
        referenceLocator: "pkg:npm/%40orchard-example/router@2.1.3"
  - SPDXID: SPDXRef-Package-orchard-example-http-core
    name: "@orchard-example/http-core"
    versionInfo: 1.8.0
218 lines total — download for the full file.

Specifications

Seed
51200
Sample Only
true
Format
SPDX
Spec Version
2.3
Serialisation
YAML
Packages
10
Relationships
11
Line Endings
LF

Testing contract

Expected to pass
Scenario
Load an SPDX document from YAML rather than JSON.
Expected result
Parser produces the same 10 packages and 11 relationships as the JSON twin, with booleans read as booleans and not as the strings 'false'/'true'.

What is a .yaml file?

YAML (YAML Ain't Markup Language) is a human-readable data-serialization format using indentation, key-value pairs, and lists, and is a superset of JSON. It supports comments, anchors, and multiple documents per file, favoring readability for configuration. Its indentation sensitivity makes it error-prone to hand-edit.

How to use this file

Use an example YAML file to test config parsers, indentation and anchor handling, multi-document streams, and safe-loading to avoid arbitrary object construction.

How to use this file for testing

“SPDX 2.3 Application SBOM (YAML)” is a deterministic Novus Examples fixture for Conversion testing, Config parsing, Schema validation. The same content exported across many formats and linked as a group, so you can convert one and diff against the expected twin.

Documented properties for this file: seed 51200 · LF · SPDX. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.

Code examples

import yaml  # pip install pyyaml

with open("spdx-2.3-application.yaml") as f:
    data = yaml.safe_load(f)
print(data)

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.