JNI bindings for Zstd native library that provides fast and high compression lossless algorithm for Java and all JVM languages.
88%
Total Score
healthy
Healthy: strong ongoing maintenance and frequent releases outweigh unpinned CI actions.
The project uses established build tools, but no security-scanning tools were detected. This is a modest transparency and maintenance gap, not evidence of an unsafe release by itself.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for a native-code library.
The latest version is on a stable major line, but it is classified as a prerelease and all recent releases share that classification, which adds some release-quality uncertainty.
Both workflows completed the audit without detected dangerous findings or untrusted checkouts, but all 24 action references are unpinned, weakening build reproducibility and update control.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-777190 New zstd-jni is vulnerable to Out-of-bounds Read in versions 1.2.0 - 1.5.7-13. | 1.2.0 - 1.5.7-13 | High |
AIKIDO-2026-954873 New zstd-jni is vulnerable to Integer Overflow in versions 1.1.1 - 1.5.7-13. | 1.1.1 - 1.5.7-13 | Medium |
AIKIDO-2026-989226 New zstd-jni is vulnerable to Out-of-bounds Read in versions 1.3.3-1 - 1.5.7-13. | 1.3.3-1 - 1.5.7-13 | High |
AIKIDO-2026-35074 New zstd-jni is vulnerable to Use-After-Free in versions 1.3.8-4 - 1.5.7-13. | 1.3.8-4 - 1.5.7-13 | High |
AIKIDO-2026-536802 New zstd-jni is vulnerable to Use-After-Free in versions 1.3.8-4 - 1.5.7-13. | 1.3.8-4 - 1.5.7-13 | High |
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.