Package Health

org.bouncycastle:bcjmail-jdk15to18

This release appears healthy and suitable for dependency use. It has a long release history with four releases in the last 12 months, is not deprecated, uses a stable major version, has Maven PGP signature provenance, and is backed by an active, non-archived organization-owned repository with substantial recent commit and issue activity. Repository tests, changelog, security policy, build tooling, and security scanning compensate for the minimal artifact scaffolding. The main reservations are concentrated commit activity, the repository not explicitly naming this package in its README, and a workflow lacking top-level token permissions; these are hygiene and resilience concerns rather than evidence of abandonment.

Latest 1.86MavenMaven

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

One contributor made about 72.5% of recent commits, creating concentration risk, although two additional contributors each contributed about 13.1% and the repository is organization-owned.

Repo package mentioncaution

The repository name does not match this package and its README does not mention the package, which raises a package-to-repository traceability concern. The name mismatch is compatible with a multi-module repository, but the lack of a README mention remains a caution.

Token permissionscaution

The analyzed CodeQL workflow lacks top-level permissions and uses job-level permissions only; this is a workflow-hardening gap, though no top-level write permissions were observed.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-912141
bcjmail-jdk15to18 is vulnerable to Improper Certificate Validation in versions 0.0.1 - 1.84.0.
0.0.1 - 1.84.0
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
org.bouncycastle:bcpkix-jdk15to18
Version 1.86

Weekly Downloads

Info

Last Published
10 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform