Package Health

bcpg-jdk14

The Bouncy Castle Java APIs for the OpenPGP Protocol. The APIs are designed primarily to be used in conjunction with the BC Java provider but may also be used with other providers providing cryptographic services. This jar is designed to work best with Java 1.4.

Latest 1.86org.bouncycastleMavenMaven

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, creating a genuine package-to-source transparency concern under this signal. The broad repository tree suggests a monorepo context, but no provided field explicitly confirms the package mapping.

Token permissionscaution

The analyzed workflow lacks top-level token permissions and relies on job-level permissions without any read-only declaration, leaving workflow permission scope less explicit than ideal.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-414766
bcpg-jdk14 is vulnerable to Integrity Check Bypass in versions 1.74 - 1.85.
1.74 - 1.85
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
org.bouncycastle:bcprov-jdk14
Version 1.86
—
—
org.bouncycastle:bcutil-jdk14
Version 1.86
—
—

Weekly Downloads

Info

Last Published
26 days ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform