Java idiomatic client for Google Cloud Storage.
93%
Total Score
healthy
Healthy: long-running releases and very active, broadly staffed maintenance support this release.
The package declares 90 runtime dependencies, which is a substantial dependency surface for a client library and increases transitive maintenance burden, though its broad cloud-client functionality makes a large profile understandable.
All 30 analyzed workflows use read-only permissions and all 237 analyzed action references are pinned, with no untrusted checkouts or script injection detected. However, only 30 of 46 workflows were analyzed and the audit reported one low-confidence cache-poisoning finding, so workflow hygiene is not completely established.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10233 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. google-cloud-storage is vulnerable to Path Traversal in versions 2.24.0 - 2.62.1. | 2.24.0 - 2.62.1 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
com.fasterxml.jackson.dataformat:jackson-dataformat-xml Version 2.18.3 | — | — |
org.codehaus.woodstox:stax2-api Version 4.2.2 | — | — |
com.fasterxml.woodstox:woodstox-core Version 7.0.0 | — | — |
com.fasterxml.jackson.datatype:jackson-datatype-jsr310 Version 2.18.3 | — | — |
com.fasterxml.jackson.core:jackson-databind Version 2.18.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.