Find files, editable templates and browser test targets by what you need to make or test. The directory below is cut by format; the two collections under it cut the same library by subject and by workflow.
The SPDX 2.3 SBOM in its YAML serialisation: the third form the specification defines alongside JSON and tag-value, and the one most often hand-edited in a repository. Every package, version, hash and licence is fictional: the tree describes nothing real.
An SPDX 2.3 tag-value document with only the mandatory document header and a single fictional package (no relationships, no files) for testing that a parser accepts a document with every optional block absent. Every package, version, hash and licence is fictional: the tree describes nothing real.
An SPDX tag-value SBOM emphasising its relationship block: one DESCRIBES edge and ten DEPENDS_ON edges that form the same two diamonds as the CycloneDX graph fixture. Every package, version, hash and licence is fictional: the tree describes nothing real.
An SPDX 2.3 tag-value SBOM that descends to file level: two fictional build outputs with SHA-1 and SHA-256 checksums, per-file licence findings, and CONTAINS relationships back to their package. Every package, version, hash and licence is fictional: the tree describes nothing real.
An SPDX tag-value SBOM that declares a non-standard LicenseRef with its extracted text and uses it inside compound expressions: the case that breaks compliance tools which assume every licence is an SPDX id. Every package, version, hash and licence is fictional: the tree describes nothing real.
An SPDX 2.3 JSON SBOM that uses the snippet section to attribute a fictional vendored fragment inside a file to a different licence, with both byte-offset and line-number ranges. Every package, version, hash and licence is fictional: the tree describes nothing real.
An SPDX 3.0 SBOM in JSON-LD (the element-graph model that replaced the 2.x document layout) describing the same fictional tree with software_Package elements and typed Relationship nodes. Every package, version, hash and licence is fictional: the tree describes nothing real.
An SPDX tag-value SBOM whose document name is a fictional container image digest rather than an application version: the naming convention image scanners use, and the SPDX counterpart of the CycloneDX container fixture. Every package, version, hash and licence is fictional: the tree describes nothing real.
An intentionally corrupt SPDX tag-value document, cut off part-way through a tag name so the final line has no colon or value. Kept small on purpose. Every package, version, hash and licence is fictional: the tree describes nothing real.
Every edge in the fictional dependency graph as one row (parent, child, declared range, resolved version, depth and whether the edge is direct), the form a spreadsheet or SQL import can aggregate. Every package, version, hash and licence is fictional: the tree describes nothing real.
A clean scan report: the case dashboards get wrong. Trivy omits the Vulnerabilities key entirely rather than emitting an empty array, so a reader that assumes the key exists throws on a passing build. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.
A Trivy-shaped image report with three result blocks (OS packages, language packages and a Dockerfile misconfiguration), so a parser must handle a Results array whose members have different keys. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.
A Trivy-shaped filesystem scan report with four SAMPLE findings against a fictional npm lockfile, one per severity band, each with a CVSS v3.1 vector, CWE class and fixed version. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.
A uv lockfile in TOML, recording an sdist and a wheel per fictional package with inline tables carrying url, hash and byte size: a newer layout than poetry.lock and a useful contrast for parser tests. Every package, version, hash and licence is fictional: the tree describes nothing real.
The written explanation of both diamonds in this category (the one that resolves to a single shared node and the peer conflict that forces a nested duplicate) with the four assertions a resolver test should make. Every package, version, hash and licence is fictional: the tree describes nothing real.
The four SAMPLE advisories flattened to one row each: the export a security review circulates, and the reference answer for any converter run against the Trivy, Grype or OSV reports here. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.
A suppression policy that gives every waiver an owner, a reason and an expiry date: the fields that stop a suppression file becoming a permanent blindfold. All four entries are SAMPLE. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.
The human-readable end of the pipeline: a triage report that records a decision and a reachability path for each of the four SAMPLE findings, matching the states asserted by the VEX documents here. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.
A modern Yarn Berry lockfile: YAML-shaped with an __metadata header, npm: protocol resolutions and cache-key-prefixed checksums, deliberately different from the Classic file in the same family. Every package, version, hash and licence is fictional: the tree describes nothing real.
A Yarn 1 lockfile in its own line-oriented grammar (quoted descriptor headers, two-space indented fields, resolved URLs with a SHA-1 fragment), which looks like YAML but is not. Every package, version, hash and licence is fictional: the tree describes nothing real.