Skip to content
Novus Examples
json901 B

Scanner Report, Truncated — Intentionally Corrupt

An intentionally corrupt scanner report: a valid Trivy-shaped JSON document cut off inside the first finding, for testing that a CI gate fails the build rather than reporting zero vulnerabilities. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

Preview — first 28 linesjson
{
  "SchemaVersion": 2,
  "CreatedAt": "2026-01-01T00:00:00Z",
  "ArtifactName": ".",
  "ArtifactType": "filesystem",
  "Metadata": {
    "ImageConfig": {}
  },
  "Results": [
    {
      "Target": "package-lock.json",
      "Class": "lang-pkgs",
      "Type": "npm",
      "Vulnerabilities": [
        {
          "VulnerabilityID": "NOVUS-SAMPLE-2026-0001",
          "PkgName": "example-logger",
          "PkgIdentifier": {
            "PURL": "pkg:npm/example-logger@3.4.1"
          },
          "InstalledVersion": "3.4.1",
          "FixedVersion": "3.5.0",
          "Status": "fixed",
          "SeveritySource": "novus-sample",
          "PrimaryURL": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0001",
          "Title": "SAMPLE advisory: fabricated improper-input-validation issue in a fictional logging library.",
          "Description": "SAMPLE advisory: fabricated improper

Specifications

Seed
51200
Sample Only
true
Scanner
Trivy-shaped
Damage
truncated mid-finding
Intentionally Corrupt
true
Line Endings
LF

Testing contract

Expected to fail
Scenario
Feed a CI security gate a report that was truncated by a killed scanner.
Expected result
The gate errors on unparseable input instead of interpreting the failure as a clean scan and letting the build pass.

What is a .json file?

JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.

How to use this file

Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.

How to use this file for testing

“Scanner Report, Truncated — Intentionally Corrupt” is a deterministic Novus Examples fixture for Error handling, JSON parsing. Deliberately corrupt and invalid files, clearly labelled, for testing how your tool fails.

Documented properties for this file: seed 51200 · damage: truncated mid-finding · LF · intentionally corrupt. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.

Code examples

import json

with open("trivy-report-truncated.json") as f:
    data = json.load(f)
print(type(data), len(data))

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.