Kotlin Standard Library
88%
Total Score
healthy
Healthy: active JetBrains maintenance and a mature release history outweigh minor workflow and package-linkage cautions.
The repository name does not match the Maven package and its README does not mention the package. Although an organization-owned monorepo can legitimately contain subpackages, the missing explicit linkage is still a transparency caution.
The single analyzed workflow has top-level write permissions and three high-confidence template-injection findings, which warrant workflow hygiene attention. However, it has no pull_request_target or workflow_run trigger, no untrusted checkout or script-injection findings, and its action use is pinned, so this is not a severe supply-chain signal.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-550292 kotlin-stdlib is vulnerable to Incorrect Default Permissions in versions 0.0.1 - 2.0.21. | 0.0.1 - 2.0.21 | Medium |
CVE-2022-24329 org.jetbrains.kotlin:kotlin-stdlib is vulnerable to Improper Locking in versions 0.0.0 - 1.5.32. | 0.0.0 - 1.5.32 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.jetbrains:annotations Version 13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.