Supply chain
Software supply-chain tooling reads a small family of documents very carefully, and getting a realistic one to test against usually means scanning a real product. This category ships them outright: CycloneDX and SPDX SBOMs in JSON, XML, and tag-value form, describing the same fictional component tree so format converters can be diffed. Lockfiles cover the major ecosystems with pinned versions and integrity hashes. Provenance and attestation fixtures follow the in-toto and SLSA shapes, VEX and OSV documents carry advisory data for invented packages, and dependency-audit reports show the output a scanner would produce. Every package name, version, hash, and advisory ID is fabricated, realistic in shape, and traceable to nothing real.
Filter supply chain on Browse · 116 files · 5 subcategories
Frequently asked questions
Which SBOM formats do you ship?+
CycloneDX in JSON and XML, and SPDX in both JSON and tag-value form, all describing the same fictional component tree, so format converters can be diffed against a known target.
Are the package names and advisory IDs real?+
Never. Components, versions, hashes, licences, and advisory identifiers are fabricated to be realistic in shape while referring to nothing that exists.
Do you include provenance and vulnerability documents?+
Yes, in-toto and SLSA-shaped attestations, VEX and OSV documents, dependency-audit reports, and lockfiles with pinned versions and integrity hashes.