Skip to content
Novus Examples
csv241 B

Severity Scoring and SLA Matrix (CSV)

A severity-band table mapping CVSS ranges to remediation SLAs and gate actions, with the finding count each band has in this fixture set — so a policy engine can be tested end to end. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

Preview — first 7 linescsv
severity,cvss_range,findings_in_this_fixture_set,remediation_sla,gate_action
critical,9.0-10.0,1,24 hours,block release
high,7.0-8.9,1,7 days,block release
medium,4.0-6.9,1,30 days,warn
low,0.1-3.9,1,90 days,track only
none,0.0,0,n/a,ignore

Specifications

Seed
51200
Sample Only
true
Format
CSV
Columns
5
Rows
5
Bands
5
Line Endings
LF (documented, not RFC 4180 CRLF)

Testing contract

Reference control
Scenario
Drive a release gate from a severity policy table.
Expected result
Evaluating the Trivy report against this matrix blocks the release on the critical and high findings and warns on the medium one.

What is a .csv file?

CSV (Comma-Separated Values) is a plain-text tabular format where rows are lines and fields are separated by commas, with quoting rules for values that contain delimiters, quotes, or newlines. It has no formal type system and depends on encoding and dialect conventions. It is the most portable format for tabular data exchange.

How to use this file

Use an example CSV to test parsers against quoting and embedded-delimiter edge cases, header handling, encoding detection, and import pipelines into databases or spreadsheets.

How to use this file for testing

“Severity Scoring and SLA Matrix (CSV)” is a deterministic Novus Examples fixture for CSV parsing, Config testing, Data import. Clean and deliberately messy CSVs — quoted commas, embedded newlines, ragged rows, odd delimiters, and encodings.

Documented properties for this file: seed 51200 · 5 rows · 5 columns · LF (documented, not RFC 4180 CRLF). Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented — never treat a finding here as real.

Feed the file to your parser and assert it handles the documented quirks — quoted delimiters, embedded newlines, ragged rows, or invalid syntax; the valid↔invalid distinction is labelled in the title.

Code examples

import pandas as pd

df = pd.read_csv("severity-scoring-matrix.csv")
print(df.head())
print(df.dtypes)

Generated by generation/supply_chain.py. Free for any use, no attribution required — license.