Package Health

bcprov-jdk15on

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5 and up.

Latest 1.70org.bouncycastleMavenMaven

70%

Total Score

caution

Usable with caveats: this release is outdated despite an active, well-backed project.

Are you affected? Scan for Free

Health Score Breakdown

Licensecaution

The package declares the Bouncy Castle Licence and includes a license file, but artifact detection identifies MIT-0, creating an apparent license mismatch that should be clarified.

Release historycaution

Version 1.70 was released in December 2021, with no registry releases in the last 12 months. The linked repository is still active, so this indicates an old release line rather than clear project abandonment.

Repo package mentioncaution

The repository name does not match this artifact and its README does not mention the package. This can be normal for a Maven subpackage in a monorepo, but it reduces direct package-to-repository transparency.

Workflow auditcaution

The single analyzed workflow has job-level permissions and no dangerous audit findings, but all three action references are unpinned, leaving avoidable build-reproducibility and action-supply-chain risk.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-45740
bcprov-jdk15on is vulnerable to Improper Certificate Validation in versions 1.46 - 1.70.
1.46 - 1.70
High
AIKIDO-2026-647831
bcprov-jdk15on is vulnerable to Uncontrolled Resource Consumption in versions 1.49 - 1.70.
1.49 - 1.70
Medium
CVE-2013-1624
org.bouncycastle:bcprov-jdk15on is vulnerable to Improper Input Validation in versions 0.0.0 - 1.48.
0.0.0 - 1.48
Medium
CVE-2017-13098
org.bouncycastle:bcprov-jdk15on is vulnerable to Observable Discrepancy in versions 0.0.0 - 1.0.3.
0.0.0 - 1.0.3
Medium
CVE-2018-5382
org.bouncycastle:bcprov-jdk15on is vulnerable to Improper Validation of Integrity Check Value in versions 0.0.0 - 1.50.
0.0.0 - 1.50
Medium

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform