SPDX 2.3 Application SBOM (YAML)
The SPDX 2.3 SBOM in its YAML serialisation — the third form the specification defines alongside JSON and tag-value, and the one most often hand-edited in a repository. Every package, version, hash and licence is fictional — the tree describes nothing real.
# SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented.
spdxVersion: SPDX-2.3
dataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT
name: orchard-gateway-4.2.0
documentNamespace: "https://sbom.orchard.example/spdx/a199a062-0945-4011-a6cd-d5c4768f4e59"
creationInfo:
created: "2026-01-01T00:00:00Z"
creators:
- "Organization: Example Softworks (fictional)"
- "Tool: novus-sbom-fixture-1.0.0"
licenseListVersion: 3.22
comment: "SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented."
packages:
- SPDXID: SPDXRef-Package-orchard-example-gateway
name: "@orchard-example/gateway"
versionInfo: 4.2.0
downloadLocation: "https://registry.orchard.example/@orchard-example/gateway/-/gateway-4.2.0.tgz"
filesAnalyzed: false
supplier: "Organization: Example Softworks (fictional)"
licenseConcluded: Apache-2.0
licenseDeclared: Apache-2.0
copyrightText: NOASSERTION
checksums:
- algorithm: SHA256
checksumValue: cde01f0c8ff9d62ef958a3de288a2f1084db14bd47e1e10ff39a52412cca613f
externalRefs:
- referenceCategory: PACKAGE-MANAGER
referenceType: purl
referenceLocator: "pkg:npm/%40orchard-example/gateway@4.2.0"
- SPDXID: SPDXRef-Package-orchard-example-router
name: "@orchard-example/router"
versionInfo: 2.1.3
downloadLocation: "https://registry.orchard.example/@orchard-example/router/-/router-2.1.3.tgz"
filesAnalyzed: false
supplier: "Organization: Example Softworks (fictional)"
licenseConcluded: Apache-2.0
licenseDeclared: Apache-2.0
copyrightText: NOASSERTION
checksums:
- algorithm: SHA256
checksumValue: d17f0a5171a018c41cdaaa2701b6c32bf49f7404032fa45e5721e2b794cd2e51
externalRefs:
- referenceCategory: PACKAGE-MANAGER
referenceType: purl
referenceLocator: "pkg:npm/%40orchard-example/router@2.1.3"
- SPDXID: SPDXRef-Package-orchard-example-http-core
name: "@orchard-example/http-core"
versionInfo: 1.8.0Specifications
- Seed
- 51200
- Sample Only
- true
- Format
- SPDX
- Spec Version
- 2.3
- Serialisation
- YAML
- Packages
- 10
- Relationships
- 11
- Line Endings
- LF
Testing contract
Expected to pass- Scenario
- Load an SPDX document from YAML rather than JSON.
- Expected result
- Parser produces the same 10 packages and 11 relationships as the JSON twin, with booleans read as booleans and not as the strings 'false'/'true'.
What is a .yaml file?
YAML (YAML Ain't Markup Language) is a human-readable data-serialization format using indentation, key-value pairs, and lists, and is a superset of JSON. It supports comments, anchors, and multiple documents per file, favoring readability for configuration. Its indentation sensitivity makes it error-prone to hand-edit.
How to use this file
Use an example YAML file to test config parsers, indentation and anchor handling, multi-document streams, and safe-loading to avoid arbitrary object construction.
How to use this file for testing
“SPDX 2.3 Application SBOM (YAML)” is a deterministic Novus Examples fixture for Conversion testing, Config parsing, Schema validation. The same content exported across many formats and linked as a group, so you can convert one and diff against the expected twin.
Documented properties for this file: seed 51200 · LF · SPDX. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.
Code examples
import yaml # pip install pyyaml
with open("spdx-2.3-application.yaml") as f:
data = yaml.safe_load(f)
print(data)Related files
- lockCargo.lock (version 4)A Rust Cargo.lock in the version 4 format — TOML [[package]] tables with a registry source, a sha256-shaped checksum and a name-only dependencies array that resolves against the other tables. Every package, version, hash and licence is fictional — the tree describes nothing real.

- txtpip requirements.txt With Pinned HashesA hash-pinned pip requirements file with two sha256 hashes per fictional package (wheel and sdist) and line continuations — the form `--require-hashes` installs demand. Every package, version, hash and licence is fictional — the tree describes nothing real.

- yamlpnpm-lock.yaml (lockfileVersion 9)A pnpm v9 lockfile with its three-section layout — importers for declared specifiers, packages for resolution metadata and snapshots for the resolved edges — pinning the same fictional tree. Every package, version, hash and licence is fictional — the tree describes nothing real.

- lockpoetry.lock (TOML)A Poetry lockfile: TOML array-of-tables entries with per-artifact sha256 hashes, a [package.dependencies] table per package and the content-hash that binds the lock to pyproject.toml. Every package, version, hash and licence is fictional — the tree describes nothing real.

- yamlAttestation Verification Policy (YAML)The policy an admission controller evaluates before an artifact is allowed through: required predicate types, an allowed-builder list, a minimum SLSA level, a transparency-log requirement and one dated exception. Every package, version, hash and licence is fictional — the tree describes nothing real.

- jsonAttestation With a Full SPDX PredicateAn in-toto statement whose predicate is an entire SPDX 2.3 document — the nesting that makes attestation payloads large and that a size-limited verifier has to cope with. Every package, version, hash and licence is fictional — the tree describes nothing real.

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.