SPDX 2.3 Application SBOM (YAML)
The SPDX 2.3 SBOM in its YAML serialisation: the third form the specification defines alongside JSON and tag-value, and the one most often hand-edited in a repository. Every package, version, hash and licence is fictional: the tree describes nothing real.
# SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented.
spdxVersion: SPDX-2.3
dataLicense: CC0-1.0
SPDXID: SPDXRef-DOCUMENT
name: orchard-gateway-4.2.0
documentNamespace: "https://sbom.orchard.example/spdx/a199a062-0945-4011-a6cd-d5c4768f4e59"
creationInfo:
created: "2026-01-01T00:00:00Z"
creators:
- "Organization: Example Softworks (fictional)"
- "Tool: novus-sbom-fixture-1.0.0"
licenseListVersion: 3.22
comment: "SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented."
packages:
- SPDXID: SPDXRef-Package-orchard-example-gateway
name: "@orchard-example/gateway"
versionInfo: 4.2.0
downloadLocation: "https://registry.orchard.example/@orchard-example/gateway/-/gateway-4.2.0.tgz"
filesAnalyzed: false
supplier: "Organization: Example Softworks (fictional)"
licenseConcluded: Apache-2.0
licenseDeclared: Apache-2.0
copyrightText: NOASSERTION
checksums:
- algorithm: SHA256
checksumValue: cde01f0c8ff9d62ef958a3de288a2f1084db14bd47e1e10ff39a52412cca613f
externalRefs:
- referenceCategory: PACKAGE-MANAGER
referenceType: purl
referenceLocator: "pkg:npm/%40orchard-example/gateway@4.2.0"
- SPDXID: SPDXRef-Package-orchard-example-router
name: "@orchard-example/router"
versionInfo: 2.1.3
downloadLocation: "https://registry.orchard.example/@orchard-example/router/-/router-2.1.3.tgz"
filesAnalyzed: false
supplier: "Organization: Example Softworks (fictional)"
licenseConcluded: Apache-2.0
licenseDeclared: Apache-2.0
copyrightText: NOASSERTION
checksums:
- algorithm: SHA256
checksumValue: d17f0a5171a018c41cdaaa2701b6c32bf49f7404032fa45e5721e2b794cd2e51
externalRefs:
- referenceCategory: PACKAGE-MANAGER
referenceType: purl
referenceLocator: "pkg:npm/%40orchard-example/router@2.1.3"
- SPDXID: SPDXRef-Package-orchard-example-http-core
name: "@orchard-example/http-core"
versionInfo: 1.8.0Specifications
- Seed
- 51200
- Sample Only
- true
- Format
- SPDX
- Spec Version
- 2.3
- Serialisation
- YAML
- Packages
- 10
- Relationships
- 11
- Line Endings
- LF
Testing contract
Expected to pass- Scenario
- Load an SPDX document from YAML rather than JSON.
- Expected result
- Parser produces the same 10 packages and 11 relationships as the JSON twin, with booleans read as booleans and not as the strings 'false'/'true'.
What is a .yaml file?
YAML (YAML Ain't Markup Language) is a human-readable data-serialization format using indentation, key-value pairs, and lists, and is a superset of JSON. It supports comments, anchors, and multiple documents per file, favoring readability for configuration. Its indentation sensitivity makes it error-prone to hand-edit.
How to use this file
Use an example YAML file to test config parsers, indentation and anchor handling, multi-document streams, and safe-loading to avoid arbitrary object construction.
How to use this file for testing
“SPDX 2.3 Application SBOM (YAML)” is a deterministic Testaroo fixture for Conversion testing, Config parsing, Schema validation. The same content exported across many formats and linked as a group, so you can convert one and diff against the expected twin.
Documented properties for this file: seed 51200 · LF · SPDX. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such, expect parsers to fail loudly rather than silently accept them.
SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented, never treat a finding here as real.
Code examples
import yaml # pip install pyyaml
with open("spdx-2.3-application.yaml") as f:
data = yaml.safe_load(f)
print(data)Generated by generation/supply_chain.py. Free for any use, no attribution required, license.
Related files
- lockCargo.lock (version 4)A Rust Cargo.lock in the version 4 format: TOML [[package]] tables with a registry source, a sha256-shaped checksum and a name-only dependencies array that resolves against the other tables. Every package, version, hash and licence is fictional: the tree describes nothing real.

- txtpip requirements.txt With Pinned HashesA hash-pinned pip requirements file with two sha256 hashes per fictional package (wheel and sdist) and line continuations: the form `--require-hashes` installs demand. Every package, version, hash and licence is fictional: the tree describes nothing real.

- yamlpnpm-lock.yaml (lockfileVersion 9)A pnpm v9 lockfile with its three-section layout (importers for declared specifiers, packages for resolution metadata and snapshots for the resolved edges) pinning the same fictional tree. Every package, version, hash and licence is fictional: the tree describes nothing real.

- lockpoetry.lock (TOML)A Poetry lockfile: TOML array-of-tables entries with per-artifact sha256 hashes, a [package.dependencies] table per package and the content-hash that binds the lock to pyproject.toml. Every package, version, hash and licence is fictional: the tree describes nothing real.

- yamlAttestation Verification Policy (YAML)The policy an admission controller evaluates before an artifact is allowed through: required predicate types, an allowed-builder list, a minimum SLSA level, a transparency-log requirement and one dated exception. Every package, version, hash and licence is fictional: the tree describes nothing real.

- jsonAttestation With a Full SPDX PredicateAn in-toto statement whose predicate is an entire SPDX 2.3 document: the nesting that makes attestation payloads large and that a size-limited verifier has to cope with. Every package, version, hash and licence is fictional: the tree describes nothing real.
