This is a very healthy release to depend on: it has a long release history, regular recent releases, stable versioning, no registry deprecation, active repository maintenance, substantial recent commit activity from multiple contributors, organizational backing, signed Maven provenance, security scanning, and a documented security policy. The main concerns are that the linked repository does not name or mention this exact package, and its single analyzed workflow lacks top-level token permissions; these are transparency and CI-hygiene cautions, but they are outweighed by the repository’s clear Bouncy Castle source structure, active maintenance, and organization ownership.
91%
Total Score
100
100
94
88
100
The repository name does not match the package name and its README does not mention the package, creating a genuine transparency concern about the exact package-to-repository linkage. The mismatch is partly understandable for a module in a broader repository, but the lack of a README mention remains cautionary.
The analyzed workflow has no top-level permissions declaration, which weakens least-privilege clarity even though it has no top-level write permissions and only job-level permissions were observed.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-127195 bcpg-jdk15to18 is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 1.84.0. | 0.0.1 - 1.84.0 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.bouncycastle:bcprov-jdk15to18 Version 1.86 | — | — |
org.bouncycastle:bcutil-jdk15to18 Version 1.86 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.