Scanner Report, Truncated — Intentionally Corrupt
An intentionally corrupt scanner report: a valid Trivy-shaped JSON document cut off inside the first finding, for testing that a CI gate fails the build rather than reporting zero vulnerabilities. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.
{
"SchemaVersion": 2,
"CreatedAt": "2026-01-01T00:00:00Z",
"ArtifactName": ".",
"ArtifactType": "filesystem",
"Metadata": {
"ImageConfig": {}
},
"Results": [
{
"Target": "package-lock.json",
"Class": "lang-pkgs",
"Type": "npm",
"Vulnerabilities": [
{
"VulnerabilityID": "NOVUS-SAMPLE-2026-0001",
"PkgName": "example-logger",
"PkgIdentifier": {
"PURL": "pkg:npm/example-logger@3.4.1"
},
"InstalledVersion": "3.4.1",
"FixedVersion": "3.5.0",
"Status": "fixed",
"SeveritySource": "novus-sample",
"PrimaryURL": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0001",
"Title": "SAMPLE advisory: fabricated improper-input-validation issue in a fictional logging library.",
"Description": "SAMPLE advisory: fabricated improper
Specifications
- Seed
- 51200
- Sample Only
- true
- Scanner
- Trivy-shaped
- Damage
- truncated mid-finding
- Intentionally Corrupt
- true
- Line Endings
- LF
Testing contract
Expected to fail- Scenario
- Feed a CI security gate a report that was truncated by a killed scanner.
- Expected result
- The gate errors on unparseable input instead of interpreting the failure as a clean scan and letting the build pass.
What is a .json file?
JSON (JavaScript Object Notation) is a lightweight, text-based data-interchange format representing objects, arrays, strings, numbers, booleans, and null. It is language-independent, human-readable, and the dominant format for web APIs and configuration. It requires a single well-formed root value.
How to use this file
Use an example JSON file to test parsers and serializers, schema validation, Unicode and number-precision handling, and API request or response processing.
How to use this file for testing
“Scanner Report, Truncated — Intentionally Corrupt” is a deterministic Novus Examples fixture for Error handling, JSON parsing. Deliberately corrupt and invalid files, clearly labelled, for testing how your tool fails.
Documented properties for this file: seed 51200 · damage: truncated mid-finding · LF · intentionally corrupt. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.
Code examples
import json
with open("trivy-report-truncated.json") as f:
data = json.load(f)
print(type(data), len(data))Related files
- jsonDependency Alerts Feed (JSON)The shape a hosted dependency-alert API returns: alerts with lifecycle state, a nested advisory, a patched-version pointer and an explicitly null dismissed_reason on the alerts that were not dismissed. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

- jsonnpm audit Report (v1, Legacy Shape)The legacy npm audit shape — numeric advisory ids, a separate actions array and dependency paths written with '>' — which tools built for the v2 report silently read as zero findings. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

- jsonpip-audit Report (JSON)A pip-audit report for the fictional Python packages. It deliberately carries no severity field — pip-audit does not assign one — which is the case a severity gate must handle without defaulting to critical. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

- jsonTrivy Clean Scan Report (Zero Findings)A clean scan report — the case dashboards get wrong. Trivy omits the Vulnerabilities key entirely rather than emitting an empty array, so a reader that assumes the key exists throws on a passing build. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

- jsonTrivy Container Image Scan Report (JSON)A Trivy-shaped image report with three result blocks — OS packages, language packages and a Dockerfile misconfiguration — so a parser must handle a Results array whose members have different keys. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

- jsonCycloneDX 1.6 Minimal SBOM (One Component)The smallest CycloneDX document that is still valid: required metadata, one fictional component, and no dependencies array — for testing that a reader handles an SBOM with nothing optional present. Every package, version, hash and licence is fictional — the tree describes nothing real.

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.