cargo tree Output
Cargo's tree output, which writes versions with a leading `v` and marks already-shown subtrees with `(*)`: close enough to npm's tree to fool a parser, different enough to break one. Every package, version, hash and licence is fictional: the tree describes nothing real.
vorchard-example/gateway v4.2.0
├── vorchard-example/router v2.1.3
│ ├── example-logger v3.4.1
│ └── example-retry v1.0.4
├── vorchard-example/http-core v1.8.0
│ ├── example-logger v3.4.1 (*)
│ └── example-json-path v2.0.5
├── example-metrics v4.0.0
│ └── example-logger v3.4.1 (*)
├── example-cache v0.9.2
│ └── example-yaml-lite v1.1.7
│ └── example-json-path v2.0.5 (*)
└── example-crypto-shim v1.2.0
Specifications
- Seed
- 51200
- Sample Only
- true
- Tool
- cargo tree (shape)
- Version Prefix
- v
- Omitted Marker
- (*)
- Drawing
- box-drawing characters
- Line Endings
- LF
Testing contract
Reference control- Scenario
- Reuse one tree parser across cargo tree and npm ls output.
- Expected result
- Parser handles the `name v1.2.3` form here and the `name@1.2.3` form in the npm fixture, producing the same edge set from both.
What is a .txt file?
TXT is a plain-text file containing unformatted character data with no styling or structure beyond line breaks. Its interpretation depends on character encoding, most commonly UTF-8, and on line-ending convention. It is the most universal and portable text container.
How to use this file
Use an example TXT to test encoding detection, line-ending (LF versus CRLF) handling, and any tool that reads or streams raw text input.
How to use this file for testing
“cargo tree Output” is a deterministic Testaroo fixture for Log parsing, Graph data, Conversion testing. Access logs and JSON-lines application logs, for testing log parsers, tailers, and ingestion pipelines.
Documented properties for this file: seed 51200 · LF. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such, expect parsers to fail loudly rather than silently accept them.
SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented, never treat a finding here as real.
Generated by generation/supply_chain.py. Free for any use, no attribution required, license.
Related files
- graphmlDependency Graph (GraphML)The dependency graph in GraphML, with typed attribute keys for node version, licence and depth and for edge range: the interchange format graph databases and analysis tools import. Every package, version, hash and licence is fictional: the tree describes nothing real.

- mmdDependency Graph (Mermaid Flowchart)The dependency graph as Mermaid, for embedding in Markdown documentation, labelled edges carry the declared range and a classDef highlights the two diamond joins. Every package, version, hash and licence is fictional: the tree describes nothing real.

- dotDependency Graph With a Cycle (Graphviz DOT)The cyclic plugin graph as DOT, with the three cycle edges highlighted. Graphviz renders it happily, which is exactly why a topological sort must be the thing that rejects it. Every package, version, hash and licence is fictional: the tree describes nothing real.

- jsonDependency Graph With Diamond Dependencies (JSON)An explicit node/edge dependency graph with in-degree, out-degree and depth precomputed, plus a diamonds array naming the two shared nodes and their parents: the reference answer for any graph builder run against the SBOMs and lockfiles here. Every package, version, hash and licence is fictional: the tree describes nothing real.

- dotDependency Graph With Diamonds (Graphviz DOT)The same diamond graph as Graphviz DOT, with edge labels carrying the declared semver range and the two diamond joins filled, renderable to SVG and diffable against the JSON twin. Every package, version, hash and licence is fictional: the tree describes nothing real.

- mdVersion Conflict and Diamond Report (Markdown)The written explanation of both diamonds in this category (the one that resolves to a single shared node and the peer conflict that forces a nested duplicate) with the four assertions a resolver test should make. Every package, version, hash and licence is fictional: the tree describes nothing real.
