Informe JSON sin procesar legible por máquina
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 184797,
"has_wiki": true,
"homepage": null,
"languages": {
"C": 1312866,
"C++": 876,
"HTML": 3807,
"Java": 33862696,
"CMake": 24388,
"Shell": 53655,
"Groovy": 10938,
"Assembly": 10678,
"Batchfile": 12956,
"Go Template": 563
},
"pushed_at": "2026-07-16T22:07:47Z",
"created_at": "2023-06-07T03:32:20Z",
"owner_type": "Organization",
"updated_at": "2026-07-16T22:07:51Z",
"description": "Bouncy Castle Java Long Term Stable (LTS) Code",
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "main",
"license_spdx_raw": null,
"primary_language": "Java",
"significant_languages": [
"Java"
]
},
"owner": {
"blog": "https://www.bouncycastle.org",
"name": "Legion of the Bouncy Castle Inc",
"type": "Organization",
"login": "bcgit",
"company": null,
"location": "Melbourne, Australia",
"followers": 296,
"avatar_url": "https://avatars.githubusercontent.com/u/4566970?v=4",
"created_at": "2013-05-30T05:06:58Z",
"is_verified": null,
"public_repos": 9,
"account_age_days": 4804
},
"license": {
"state": "absent",
"spdx_id": null,
"raw_spdx": null,
"file_present": false,
"scorecard_found": false,
"profile_has_license": false
},
"activity": {
"releases": [],
"recent_commits": [
{
"oid": "053e59f6a16a66b1f83030ab06643f8507c49d39",
"body": null,
"is_bot": false,
"headline": "version bump",
"author_name": "mwcw",
"author_login": "mwcw",
"committed_at": "2026-07-16T11:05:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a65b4b3c674ccdd44ecf4d8779906984e85d2b3b",
"body": null,
"is_bot": false,
"headline": "added tests for hardening SHA3 and SHAKE restore",
"author_name": "mwcw",
"author_login": "mwcw",
"committed_at": "2026-07-16T10:09:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f5df0d2ac1fce2454a8efb55ffd5b08011858c89",
"body": null,
"is_bot": false,
"headline": "additional hardening of SHA-3/SHAKE persistence code",
"author_name": "mwcw",
"author_login": "mwcw",
"committed_at": "2026-07-16T08:11:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f101b232c5d3e07ecdd504210a57e43831d6cd65",
"body": null,
"is_bot": false,
"headline": "removed old bc.test.data.home def",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-15T07:37:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "48cfccfc5888c20cfbc8f3a816ded84d12065faa",
"body": null,
"is_bot": false,
"headline": "KCCM patch",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-15T03:57:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6ae30970a03628fc7b8e47cad2ffd4b1c0b48e97",
"body": null,
"is_bot": false,
"headline": "version bump",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-15T02:07:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5079e61bd15220a00f5be3b4a119f2bb0d7602b4",
"body": null,
"is_bot": false,
"headline": "Merge branch 'main' of gitlab.cryptoworkshop.com:root/bc-lts-java",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T23:53:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3c7c08524c9ded90087da61470774e34738ad171",
"body": null,
"is_bot": false,
"headline": "sync update",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T23:53:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d446fd719763a7736844a829283184acd6f5e6de",
"body": null,
"is_bot": false,
"headline": "test using interface not instance type",
"author_name": "mwcw",
"author_login": "mwcw",
"committed_at": "2026-07-14T15:25:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9a72c6fe9c9dd3d973b762da33d982c1367d86f0",
"body": null,
"is_bot": false,
"headline": "file sync",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T13:03:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ed39ef34e97467af4d9fc3b25d6404a3982fde3f",
"body": null,
"is_bot": false,
"headline": "better variant selection on arm",
"author_name": "mwcw",
"author_login": "mwcw",
"committed_at": "2026-07-14T12:23:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "186950663c9358d5b8b621583faafcccde2ec421",
"body": null,
"is_bot": false,
"headline": "bc.test.data.home removal",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T12:02:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "de475048ec200436adb7a6973148710310cbc477",
"body": "… small)\n\nBcAEADUtil.PGPAeadOutputStream.writeBlock() encrypted each chunk in place into the\nchunk-sized 'data' buffer, then called doFinal(data, 0). That assumes the cipher emits all\nciphertext during processBytes and only the 16-byte MAC at doFinal - true for the pure-Java\nGCM but NOT for the nati\n[…]\nVerified after the fix: PGPAeadTest,\nAEADProtectedPGPSecretKeyTest, PGPEncryptedDataTest all Okay on BOTH vaes-native and java;\nAEADWithArgon2Test OK; bcpg japi 100%/0 (internal class, no API change).",
"is_bot": false,
"headline": "Fix OpenPGP AEAD encryption on the native GCM path (output buffer too…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T11:39:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e3c1137ba4c480d4acb8cd956f1c0c1bc42d8904",
"body": "…overage, OCSP revocation suite\n\nVerbatim-adopted stale test files (compile + pass against current LTS code):\n- pkcs/test/PKCS8Test: PBKDF2 iteration-count upper-bound test (PBE_MAX_ITERATION_COUNT).\n- cms/test/BcEnvelopedDataTest: adds testProvidedKeyAsKeyParameter, testPasswordCamellia256,\n testP\n[…]\nAeadRoundTrip needs ARIA/SM4 AEAD matching absent from the LTS bc\nEnvelopedDataHelper) and cert/cmp/AllTests (testComposite needs the legacy SPHINCS+\n1.3.6.1.4.1.18227.2.1 signer, curated out of LTS).",
"is_bot": false,
"headline": "Adopt stale pkix test residuals: PKCS8 PBKDF2 bound, enveloped-data c…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T08:23:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7fb764e6a655d181c295763f8f5a7a5f7d7ef614",
"body": "…ypass, BKS hardening\n\nVerbatim-adopted stale test files (compile + pass against current LTS provider code):\n- SignatureTest: strict no-NULL RSA DigestInfo verification test (exercises the\n PKCS1_STRICT_DIGESTINFO path).\n- PKIXNameConstraintsTest: name-constraint bypass hardening suite (X509_ALLOW_\n[…]\nst (native/\nLTS-ahead), HMacTest (dropped OldHMac), SimpleTestTest/PrivateConstructorTest/RegressionTest/\nPKCS12StoreTest/nist AllTests (dropped PQC provider / XChaCha / missing sibling test classes).",
"is_bot": false,
"headline": "Adopt stale prov test residuals: strict-DigestInfo, name-constraint b…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T08:21:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "99ac8dcd3c13cfe2cc824d3cb4ef04802d5b1ea3",
"body": "…ixes\n\nThe stale test-file scan surfaced negative/regression tests that were behind upstream -\nseveral paired with a main-source residual the test exercises. Adopt both sides:\n\nPaired main-source fixes (clean residuals, japi bccore+bcprov 0/0):\n- engines/EthereumIESEngine: apply the K2-first static-\n[…]\nTest(15), ECJPAKECurveTest pass.\nNot adopted (LTS-ahead/curated - would regress): SLHDSATest, GCMTest short-IV, AESVectorFileTest,\nand the DHTest (coupled to the deferred DHParameters L-check change).",
"is_bot": false,
"headline": "Adopt stale core test residuals + their paired main-source security f…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T08:20:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "02533afe5b093b0e85e031a3ebc8f300be9ed467",
"body": "…ut, overflow, validation fixes\n\nThe initial core residual triage filtered to ltsOnly<=2; this sweeps the ltsOnly 3-10 bucket\n(60 main-source candidates, triaged by 5 agents) and adopts the genuine STALE HIGH/MED. All\nverbatim-safe (japi bccore + bcprov stay 100%/0):\n\nHIGH:\n- pqc/crypto/lms HSSPriva\n[…]\n octet-string change needs the paired decode update and is\nblocked by curated-out CMCE/FrodoKEM branches). LOW perf-only drift left as-is (SecP*Curve x12,\nKeccakDigest, ISAACEngine, additive getters).",
"is_bot": false,
"headline": "Adopt core ltsOnly-3-10 bucket residuals: side-channel, malformed-inp…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T08:03:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "14fced1eb94f22877064521001aaaee009a7cb28",
"body": "…rBuilder\n\nLTS's CompositePublicKey swaps the intuitive accessor naming: getAlgorithmID() returns an\nAlgorithmIdentifier, getAlgorithmIdentifier() returns the ASN1ObjectIdentifier. The\nbuild(PublicKey) verifier gated its generic-composite (id_composite_key) branch on\ngetAlgorithmID().equals(MiscObje\n[…]\nllTests (14) pass. The\ncorrected branch mirrors upstream's per-component verify logic; it could not be positively\nexercised here because no passing in-tree test reaches generic-composite verification.",
"is_bot": false,
"headline": "Fix dead generic-composite verify branch in JcaContentVerifierProvide…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T07:44:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "45a1d9f670544c45f53544381890053e904812d6",
"body": "…siduals skill\n\nCapture this session's methodology so future work is repeatable:\n\n- CLAUDE.md \"hidden stale-source residual\": add the DIRECT detector - a residual scan for\n `recorded index == upstream hash AND local source != upstream` - which finds residuals\n without compiling (compile/tests rema\n[…]\nanged ctor, changed return/param type, class\n made abstract, method added to a public interface).\n- New skill .claude/skills/reconcile-residuals: the full scan -> triage -> adopt -> japi\n procedure.",
"is_bot": false,
"headline": "Document the residual scan + japi gate in CLAUDE.md; add reconcile-re…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T07:42:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a7a23f984734562bd4701d7265942575f02f1577",
"body": "The MED ML-KEM zeroization was reverted in c62fb86c because the upstream verbatim adoption\nalso made MLKEMSpi abstract and changed the Encapsulator/Decapsulator public constructors\n(ABI breaks). Re-apply only the zeroization against the baseline SPIs, with no signature,\nconstructor, or class-hierarc\n[…]\neturned key is built), so it is purely\ndefensive hygiene. Verified: MLKEMTest (14) passes with the jdk17 overlay active; bcprov\njapi 100%/0. MLKEMSpi stays concrete and the constructors are untouched.",
"is_bot": false,
"headline": "Re-apply ML-KEM key-material zeroization in a binary-compatible way",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T07:39:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1c38cdbefabdf2f0869123047071cb39c032818e",
"body": "…y agreement (#790)\n\nHidden stale-source residual: CMSUtils.ecAlgs did not include the BSI TR-03111 ECKA-EG\nwith X9.63 KDF OIDs, so CMS EnvelopedData/AuthEnvelopedData recipients using those (BSI\nTR-03109-3 / ICAO 9303-11 eID/eIDAS decryption, github #790) were not dispatched down the\nEC key-agreeme\n[…]\n Needs a proper merge with\n the LTS GCM handling.\n- pkix/jcajce/PKIXCertPathReviewer: diverges bidirectionally (LTS-ahead + stale + a\n blocked ETSI QcType block); too entangled for a safe MED merge.",
"is_bot": false,
"headline": "Adopt pkix residual (surgical): route BSI ECKA-EG algorithms as EC ke…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T07:33:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "de5e8aa92c06f5f586ca919a690e2ebb3eaf952e",
"body": "…count guard + algorithm coverage\n\nHidden stale-source residuals from the pkix-index scan (recorded index at upstream, local\nbehind), adopted verbatim after confirming each is binary-compatible (japi bcpkix 0/0):\n\n- cms/bc/BcPasswordRecipient (HIGH): reject a NEGATIVE PBKDF2 iteration count. The loc\n[…]\ne correct call is\ngetAlgorithmIdentifier()) - left unfixed because CompositeKeyTest fails independently\n(SPHINCS+ 1.3.6.1.4.1.18227.2.1 not registered standalone), so the fix cannot be validated here.",
"is_bot": false,
"headline": "Adopt pkix-index residuals (verbatim-safe HIGH+MED): PBKDF2 negative-…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T07:28:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "68110e6d3dca0e854f5d7416726741dc8b1665ed",
"body": "Hidden stale-source residual from the tls-index scan (recorded index at upstream, local\nbehind). ProvTlsServer lacked the getHandshakeTimeoutMillis() override, so a configured\nJSSE server-side handshake timeout was never enforced (a slow-handshake DoS vector);\nContextData.getHandshakeTimeoutMillis()\n[…]\ncryptionMethodGenerator\nneeds the instance JceAEADUtil(helper) HKDF form, which depends on the curation-diverged\nJceAEADUtil, and adds throws PGPException). The rest of pg was intentional/local-ahead.",
"is_bot": false,
"headline": "Adopt tls residual: honour server handshake timeout in ProvTlsServer",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T07:21:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c62fb86c09347a0cb465ee69a6ffcc81b5bb8e3d",
"body": "… gate)\n\njapi-compliance-checker (bcprov 2.73.11 -> 2.73.12) flagged 4 removed methods + 1\nbecame-abstract - all introduced by this session's prov residual adoptions, violating\nthe no-removals API policy. Revert the offending changes to restore 100% binary/source\ncompatibility (verified: bcprov, bcc\n[…]\nse-chaining, etc.); drops only the members that broke the ABI. CertTest/prov\nRegressionTest clean (the transient CertificateFactory NPE was a stale build/resources\ndir, fixed by processTestResources).",
"is_bot": false,
"headline": "Revert binary-incompatible parts of the prov residual adoptions (japi…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T07:17:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cc3b069b48328c898d73c4d7205b67067c38f165",
"body": "…precated helpers\n\nRemaining LOW hidden stale-source residuals from the prov-index scan (recorded index at\nupstream, local behind):\n\n- Exception cause-chaining (github #2309) - preserve the originating exception instead of\n discarding it: MLKEMCipherSpi, asymmetric/util/BaseCipherSpi, symmetric/uti\n[…]\nr ECDHCBasicAgreement+X9IntegerConverter).\n\nVerified: prov RegressionTest 0 failures (excl. pre-existing CertPathBuilder), BCFKS: Okay.\nEight adopted verbatim (match index); BcFKSKeyStoreSpi surgical.",
"is_bot": false,
"headline": "Adopt prov-index LOW residuals: exception cause-chaining (#2309) + de…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T06:44:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "46ed24974b718db286cc002da03205c993ec8e55",
"body": "…omposite malformed-input guards\n\nHidden stale-source residuals from the prov-index scan, applied surgically (verbatim\nadoption blocked by LTS curation - dropped X509AttributeCertificate/X509Principal, the\ninternal.asn1.iana relocation, and the LTS-ahead CompositePublicKey.getAlgorithmIdentifier\nAPI\n[…]\notEmpty signature change + per-URI failure\ncollection) is entangled with the known pre-existing CertPathBuilder AKI-narrowing gap;\nand SHA3 KMAC (needs KMacSpi + KMACAlgorithmParameters ported first).",
"is_bot": false,
"headline": "Adopt prov-index residuals (surgical): fail-closed CRL revocation + c…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T06:29:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8b75bd2112d99bc1ffc72b888ea59a99ff0a2d7b",
"body": "…IA CCM fix, CRL cache TTL, ML-KEM zeroization\n\nHidden stale-source residuals from the prov-index scan (recorded index at upstream,\nlocal behind):\n\n- rsa/DigestSignatureSpi (HIGH): enforce PKCS1_STRICT_DIGESTINFO on RSA signature verify\n when the operator opts in (org.bouncycastle.pkcs1.strict_dige\n[…]\n excl. the pre-existing\nCertPathBuilder network timeout); MLKEMTest (14) + MLKEMKeyPairGeneratorTest (4) pass;\njdk17 source set compiles. All adopted match their recorded index except ARIA (curation).",
"is_bot": false,
"headline": "Adopt prov-index residuals (verbatim-safe): RSA strict DigestInfo, AR…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T06:20:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e7509875bef0ccaf5cd38c10f8b0c7d12532d22e",
"body": "…iveTimeStamp refactor)\n\nHidden stale-source residuals found by a local-vs-upstream scan of the util index\n(recorded index already at the upstream hash, local source behind). A full scan of the\n593 util entries surfaced only these; the rest were intentional curation, cosmetic, or\nLTS-ahead.\n\nAdditiv\n[…]\nialNumber\n(LTS is ahead / has a guarded ctor).\n\nVerified: util asn1 RegressionTest (0 failures), util OER AllTests; pkix compiles clean\nand TSP (47) + CMS (338) AllTests pass against the changed util.",
"is_bot": false,
"headline": "Adopt upstream util-index residuals (deprecated compat getters + Arch…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T06:08:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a192eb1526cd8e527ff0f30d54ad236b4ddd9af1",
"body": "…al/Sequence factories\n\nHidden stale-source residuals (recorded index at upstream, local behind); a coherent\nASN.1-infrastructure cluster adopted together:\n\n- ASN1UniversalType + ASN1TaggedObject: add fromExplicit(), which validates that an\n explicitly-tagged object actually holds the expected prim\n[…]\nExternal.fromSequence already present).\n\nNo test asserted the changed exception text. All five match their recorded index.\nVerified: asn1 RegressionTest and core crypto RegressionTest both 0 failures.",
"is_bot": false,
"headline": "Adopt upstream ASN.1 core residuals: explicit-tag validation + Extern…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T05:50:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0de6efe04d1959781c056d24dbd0adf02f3cf941",
"body": "…de hardening, helpers\n\nHidden stale-source residuals (recorded index at upstream, local behind):\n\n- asn1/x500/style BCStyle + RFC4519Style: validate country code is exactly 2 chars\n (ISO 3166-1 / X.520) and CN <= 64 chars on name construction, plus s/dnq lookups.\n X500NameTest carried an invalid \n[…]\n is blocked by deliberate curation.\n\nVerified: X500NameTest, asn1 RegressionTest (0 failures), core crypto RegressionTest\n(0 failures) all pass. All seven main-source files match their recorded index.",
"is_bot": false,
"headline": "Adopt upstream MED-risk core residuals: X.500 name validation, hashCo…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T05:46:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7e0ee5567728d24f8da75d90aab3fc0fe84dfebc",
"body": "Hidden stale-source residuals (recorded index at upstream, local behind):\n\n- ECIESKEMExtractor: apply implicit rejection - an ephemeral point that decodes to the\n identity (infinity) now yields a pseudo-random shared secret derived from the input\n rather than a fixed/zero key, so an invalid encaps\n[…]\nest relied on the old throw/message.\n\nAll six adopted verbatim; each matches its recorded index. Verified: LMSTest (13),\nLMSTests/HSSTests/TypeTests/LMSKeyGenTests, and ECIESKeyEncapsulation all pass.",
"is_bot": false,
"headline": "Adopt upstream reject-malformed hardening for ECIES-KEM and LMS/HSS",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T05:41:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "52ec79910e3c87522ae3b642217e4a276e8a4320",
"body": "Hidden stale-source residuals (recorded index at upstream, local behind). The rfc7748\nX25519/X448 scalar-multiplication entry points (calculateAgreement, generatePrivateKey,\nscalarMult*) now null-check their key/random/output arguments and validate the k/u/r\narray offsets via Arrays.validateSegment \n[…]\nrithmetic. Arrays.validateSegment\nalready exists in this tree.\n\nAdopted verbatim; both match their recorded index. Verified: X25519/X448 SimpleTests\npass and core crypto RegressionTest has 0 failures.",
"is_bot": false,
"headline": "Adopt upstream null/bounds validation in X25519 and X448",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T05:39:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f2da426b990c140eea3c24db60f45e3ea49e07f2",
"body": "…eters\n\nHidden stale-source residuals (recorded index already at upstream, local behind):\n\n- DHPublicKeyParameters / DSAPublicKeyParameters: bound the modulus bit-length (default\n 16384, overridable via org.bouncycastle.dh.max_size / dsa.max_size) before the\n super-linear legendre/modPow validatio\n[…]\n hash.\n\nFollow-up (separate module): pg PGPUtil applies the MAX_PASSES/MAX_PARALLELISM caps to\nthe OpenPGP Argon2 S2K path and diverges from upstream - to be reconciled in the pg\nmodule residual scan.",
"is_bot": false,
"headline": "Adopt upstream DoS caps for DH/DSA modulus size and Argon2 cost param…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T05:36:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f516340426b30be9381bfb2e765bacdc5f7cfa51",
"body": "…1 factories\n\nHidden stale-source residuals found by a local-vs-upstream scan of the core index\n(recorded index already at the upstream hash, so check-indexes is blind; local source\nbehind). These continue the malformed-input hardening line of d3adfc85/f1c80e37: each\ngetInstance/constructor now reje\n[…]\nject casts for\nsafe getInstance).\n\nAll 13 adopted verbatim from upstream; each now matches its recorded index hash.\nVerified: asn1 RegressionTest and core crypto RegressionTest both pass (0 failures).",
"is_bot": false,
"headline": "Adopt upstream malformed/empty-SEQUENCE decode guards in 13 core ASN.…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T05:33:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "285cd4be411f7f6fdd0a59dd86a2f314bcea5245",
"body": "a3202734 adopted the upstream IESEngine fix that reorders the static-key (V.length==0)\nkey split to put the MAC key K2 at a fixed prefix (closing a cross-message forgery in\ndeterministic static-key mode). That changes the stream-mode ciphertext, but ECIESTest\nstill pinned the pre-fix vector (468d898\n[…]\ngression test (knownPt/forgedPt)\nthat demonstrates the fix. The committed a3202734 engine reproduces the upstream vector\nexactly, confirming the hand-merge matches upstream behaviour. Now ECIES: Okay.",
"is_bot": false,
"headline": "Update stale ECIESTest vector to match the IESEngine static-key CVD fix",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T05:19:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3a80643cc5847433a9436a5f474aead0a02efd01",
"body": "OpenSSHSpecTests (byte-identical to upstream) failed with \"encrypted keys not\nsupported\": core OpenSSHPrivateKeyUtil was a hidden stale-source residual (index\nalready at the upstream hash, but the local source was the older 396-LOC version that\nrejected encrypted keys). Adopting it surfaced a cascad\n[…]\nssing-passphrase negative cases), and\nOpenSSHSpec: Okay again with the jdk15 overlay classes shadowing the base;\nRSATest/DSA-ECDSA/EdEC still Okay. Full main+test compile (incl. MR source sets) clean.",
"is_bot": false,
"headline": "Port encrypted OpenSSH private-key support (stale-residual cascade)",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T05:12:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f3287d22927898b5a420de8d4f4d1765cc77122d",
"body": "Both test sources were hidden stale-source residuals: their index entries were bumped\nto the current upstream hash during a bulk sync, but the local test source lagged\nbehind the upstream behavioural changes, so they failed against the (already current)\nLTS main code. check-indexes cannot see this -\n[…]\n upstream and already throws; only the\n test still asserted the old return-null contract. Adopt the upstream expect-throws\n assertions.\n\nVerified: CertPathValidator: Okay, CertTest: Okay standalone.",
"is_bot": false,
"headline": "Adopt upstream test updates for two stale JCE tests (github #457, #2327)",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T04:53:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3e52d60a2361833c1150eae5e8f41760e3f1666d",
"body": "… decoder/harness findings\n\nAddresses the 13 findings from the e107256b bulk-sync review (review_14Jul2026_2.md).\n\nDead provider registrations (getInstance threw for advertised algorithms):\n- A1 rsa/KeyFactorySpi: port the nested PSS AlgorithmIdentifier-carrying subclass\n so KeyFactory.getInstance(\n[…]\nA/Digest/CipherStreamTest/XOF all\nOkay), NistCertPathTest2 (208), OERInputStreamLimitTest (2), PGPv6KeyTest, and a\ndirect KeyIdentifier multi-element scan check all pass; full main+test compile clean.",
"is_bot": false,
"headline": "Remediate the e107256b review: restore dead JCE registrations and fix…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T04:47:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5726a0854c9d16f739ef3c392f99f736ed3041e9",
"body": "…sistency)\n\nA module-info vs OSGi-Export-Package vs shipped-packages audit found several\npackages that the LTS jdk1.9 module descriptors had dropped relative to upstream\nwhile the packages are still shipped and OSGi-exported (bnd Export-Package glob in\nbuild.gradle) - so they were invisible to --mod\n[…]\n09 legacy, etc.) correctly absent from both.\n\nVerified: :util:jar / :prov:jar compile the descriptors (javac validates each\nexports against a real package); japi bcutil 0/0, bcprov 0 removed / 0 high.",
"is_bot": false,
"headline": "Restore module-info exports dropped from bcutil/bcprov (JPMS/OSGi con…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T04:09:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e4c64018db089c7932ab2a2e5a6a7eea83b769e2",
"body": "…, boundary test)\n\n- F1: PGPUtil.makeKeyFromPassPhrase dereferenced s2kCalculator.getType() three\n lines before its own null-guard, so a decryptor built without a calculator NPE'd\n (escaping the throws PGPException contract) instead of throwing the intended\n PGPException; moved the null check abo\n[…]\np - that would need 16 GiB.)\n\n657b85fb F4 (ARGON2 SPI validating only key length) left as a documented,\nupstream-identical contract nit. Verified :pg:test green; japi bcpg / bcprov\n0 removed / 0 high.",
"is_bot": false,
"headline": "Address 657b85fb Argon2 review findings (null-guard, empty passphrase…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T04:05:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0b195bf5308b736283635984e449e777b6af25de",
"body": "…ecipients\n\nCloses 3dcc650c F2: the RSA-KTS-KEM key-transport recipient family\n(JceKTSKeyTransRecipient and its Enveloped/Authenticated subclasses) implemented\nKeyTransRecipient directly and so was not covered by the recipient\ncontent-algorithm allow-list / AEAD tag-size floor added in 3dcc650c - it\n[…]\nport\nrecipients. Opt-in (unset allow-list allows all), so no behaviour change by default.\n\nVerified: :pkix:test green; japi bcpkix 0 removed / 0 high (added superclass shows\nas low, setters additive).",
"is_bot": false,
"headline": "Extend the CMS content-algorithm allow-list / AEAD tag floor to KTS r…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T04:05:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fe04565ecc2f3d2ad3d87082f79149ed953df73b",
"body": "Fixes from the per-commit reviews of 3a37cd58, 3dcc650c and 2cfb92e2:\n\n- 3a37cd58 (RSASSA-PSS #721) F1/F2/F3 - BcRsaPssUtil.createSigner parses an\n attacker-controlled, unauthenticated RSASSA-PSS AlgorithmIdentifier during\n signature verification. Now: bound the salt length (reject negative / > 51\n[…]\ns not covered by the allow-list -\nopt-in coverage gap matching upstream scoping).\n\nVerified: :pkix:test green; japi bcpkix 2.73.11 -> 2.73.12 is 0 removed / 0 high\n(KEMRecipientId.equals is additive).",
"is_bot": false,
"headline": "Address review findings on the pkix follow-up commits (param validation)",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T03:43:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6153acf3e79d2297e2c5bd27690f50a4cd2dbead",
"body": "…ontract)\n\nFollow-up fixes to the pkix hardenings commit b7a2f048, from a dedicated re-review:\n\n- M1: checkScryptCost (JcePKCSPBEInputDecryptorProviderBuilder and the identical\n copy in JceOpenSSLPKCS8DecryptorProviderBuilder) bounded only N and r; a large\n parallelization parameter p could still \n[…]\ndle (previously only the English bundle had them).\n\nC1 (extracting the triplicated cost-check helpers) deferred as a pure refactor.\nVerified: :pkix:test green; japi bcpkix 0 removed / 0 high-severity.",
"is_bot": false,
"headline": "Address b7a2f048 review findings (scrypt p-bound, EST drain, verify c…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T03:38:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a32027340ad629f7866f102256b6b81d993defa5",
"body": "… (CVD)\n\nA CVD-report audit against the LTS release surfaced five core files that were\nhidden stale-source residuals: their index already recorded the current upstream\nhash (so check-indexes reported them clean) but the LTS source was an older\nversion missing security fixes upstream bc-java already \n[…]\ndy recorded upstream, so no index change.\n\nVerified: :core:test / :pkix:test green apart from native-availability tests\n(no native libs here); japi bccore 2.73.11 -> 2.73.12 is 0 removed / 0 problems.",
"is_bot": false,
"headline": "Fix five stale core crypto/ASN.1 files behind upstream security fixes…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T03:38:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "be3841dc0b4e9a1779b97b1d6c3f9c1259a3f5ac",
"body": "The #2254 fix — ProvOcspRevocationChecker must reject a manually-supplied OCSP\nresponse whose signature does not verify, rather than silently accepting it —\nis already present in LTS (ProvOcspRevocationChecker is byte-identical to\nupstream). Upstream's regression test was missing, so adopt\nOCSPExcep\n[…]\ntry for ASN1PKIXNameConstraintValidator.java\n(deleted in commit f8a1d833 but its index line was left behind — now dangling).\n\nVerified :pkix:test green (OCSP suite incl. the new negative test passes).",
"is_bot": false,
"headline": "Add OCSP exceptional-signature-rejection test (github #2254)",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T03:06:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "284bac70c85653ed3d09b8c51dcea5ebaed179e0",
"body": "The header-injection guard already exists in LTS (SMimeUtils.checkHeader\nrejects a header name/value containing CR/LF, called from the SMIMEEnveloped/\nSMIMESignedWriter builders), but upstream's regression test was not present.\nAdopts SMIMEWriterHeaderInjectionTest verbatim and registers it in the m\n[…]\nuard is actually exercised (CRLF/bare-LF in header name or\nvalue must throw IllegalArgumentException; clean headers accepted).\n\nVerified :pkix:test green (SMIMEWriterHeaderInjectionTest 5 tests pass).",
"is_bot": false,
"headline": "Add and wire the S/MIME writer header-injection test",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T03:01:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0d585b26ba39e7bbe8caf82b22e79ea3a839de42",
"body": "…gnostic)\n\nPKIXCertPathReviewer now emits a CertPathReviewer.ncNonCACert notification when\na certificate in the path is not a CA (basicConstraints == -1) yet carries a\nnameConstraints extension. RFC 5280 sec. 4.2.1.10 restricts name constraints to\nCA certificates and the path-validation algorithm ne\n[…]\ne legacy org.bouncycastle.x509 reviewer, so that half of\nthe test is dropped).\n\nVerified :pkix:test green (CheckNameConstraintsTest incl. the new case);\njapi bcpkix unchanged (diagnostic is internal).",
"is_bot": false,
"headline": "Flag name-constraints extension on a non-CA certificate (reviewer dia…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T03:01:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "27c479071e905a856a3afb6b7dff45f6675e7e09",
"body": "The sole mail recorded-vs-upstream mismatch is jdk1.9/module-info.java, whose\ndivergence is entirely LTS-specific: the module name (org.bouncycastle.lts.mail),\nLTS-named requires (lts.prov / transitive lts.pkix), and a commented-out\nexamples export. Upstream's explicit `requires org.bouncycastle.uti\n[…]\nLTS transitively (mail -> transitive lts.pkix -> transitive\nlts.util), so the descriptor is functionally correct. Reviewed and left\ndiverged; index advanced to the upstream baseline. No source change.",
"is_bot": false,
"headline": "Reconcile mail: bump module-info baseline (LTS-diverged descriptor)",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T02:40:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fefb9289e7d724c78486f1db7c81e7ebb97e07c0",
"body": "…525)\n\nReviews all 13 tls recorded-vs-upstream index mismatches. One self-contained\nhardening adopted:\n\n- jsse/provider/HostnameUtil: the deprecated Subject-CN-as-hostname fallback\n (RFC 9525 sec. 6.3; a Name-Constraints bypass surface) is now gated behind\n Properties.JSSE_HOSTNAME_CHECK_CN_FALLBA\n[…]\nhe CN-fallback default flip breaks no LTS test);\njapi bctls 2.73.11 -> 2.73.12 is 0 removed / 0 problems (HostnameUtil is\ninternal). Index: advanced all 13 reviewed tls files to the upstream baseline.",
"is_bot": false,
"headline": "Reconcile tls to upstream: gate legacy CN-as-hostname fallback (RFC 9…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T02:37:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "657b85fb3449c4b09f9df33a5be8160a68ce387c",
"body": "…ARGON2 + S2K hardening\n\nReviews all 21 pg recorded-vs-upstream index mismatches and adopts the\nupstream OpenPGP Argon2 refactor plus a malformed-S2K robustness fix.\n\npg (OpenPGP):\n- Adopt upstream's pluggable memory-hard S2K architecture: new\n PGPS2KCalculator interface + BcPGPS2KCalculator + JceP\n[…]\nlity tests (no native libs here). japi 2.73.11 ->\n2.73.12: bcpg and bcprov both 0 removed / 0 high-severity. Indexes: added the\n6 new files, advanced the 21 reviewed pg files to the upstream baseline.",
"is_bot": false,
"headline": "Reconcile pg to upstream: Argon2 PGPS2KCalculator architecture + JCE …",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T02:28:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "119fd9ca49c08719b47ed513a0eb395343c61daf",
"body": null,
"is_bot": false,
"headline": "reworked exception",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T01:08:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f8a1d833317f29d2ec0be0e144b3560aec652bc9",
"body": null,
"is_bot": false,
"headline": "unused package protected",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T00:57:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3dcc650c2297e51f2fd2b4e6aca126c053ecfa67",
"body": "Ports upstream's recipient-side downgrade defenses so a CMS recipient can\nconstrain what it will recover:\n\n- setAllowedContentAlgorithms(Set): reject recovery when the message's\n content-encryption algorithm is not in the caller's allowed set\n (CMSAlgorithmNotAllowedException), blocking an attacke\n[…]\n 2.73.12\nstill 0 removed / 0 high (the added superclass shows as 7 low type-changes;\nthe new setters/classes are additive). Index: added the three new classes,\nadvanced the ten recipients to upstream.",
"is_bot": false,
"headline": "Add CMS recipient content-algorithm allow-list and AEAD tag-size floor",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T00:54:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3a37cd582a167699ff3fbd3ec59a02da9990053f",
"body": "…721)\n\nBcRSAContentSignerBuilder and BcRSAContentVerifierProviderBuilder hardcoded\nRSADigestSigner (PKCS#1 v1.5) regardless of the signature algorithm OID, so an\nid-RSASSA-PSS AlgorithmIdentifier produced/verified PKCS#1 v1.5 bytes that no\nPSS verifier accepts — the lightweight Bc path silently disa\n[…]\nen (operator AllTests 5 -> 7 tests, all pass); japi\nbcpkix 2.73.11 -> 2.73.12 still 0 removed / 0 high (BcRsaPssUtil is\npackage-private). Index: added BcRsaPssUtil, advanced both builders to upstream.",
"is_bot": false,
"headline": "Route id-RSASSA-PSS through PSS in the Bc operator builders (github #…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T00:21:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b0e064cf62f14ea55f0875bd34886b53c4e86d18",
"body": "DefaultDigestAlgorithmIdentifierFinder mapped pure id_ml_dsa_44/65/87 to\nid_shake256 for the CMS SignerInfo message-digest. draft-ietf-lamps-cms-ml-dsa\nrequires SHA-512 support and uses the id-sha512 identifier when SHA-512 is\nused; upstream defaults to id_sha512 here. Align LTS so freshly-signed CM\n[…]\nasserts shake256 for ML-DSA; the pre-existing testMLDsa* blocks remain\ncommented, matching upstream). Index baseline for the finder advanced to\nupstream. No API change (internal digest-map data only).",
"is_bot": false,
"headline": "Default ML-DSA CMS digest to SHA-512 (was SHAKE-256)",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-14T00:12:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2cfb92e26c88f9be4dd2176e0d504ed298e0b690",
"body": "…pient id\n\nKEMRecipientInformation used a KeyTransRecipientId placeholder (with TODOs) for\nits RID and exposed none of the KEM fields. Ports upstream's KEMRecipientId\n(new public class in org.bouncycastle.cms, extends PKIXRecipientId with\nRecipientId.kem) and updates KEMRecipientInformation to build\n[…]\n1 -> 2.73.12 still 0 removed /\n0 high-severity (KEMRecipientId + the three accessors are additive). Index:\nadded the KEMRecipientId entry and advanced the KEMRecipientInformation\nbaseline to upstream.",
"is_bot": false,
"headline": "Port KEMRecipientId; wire KEMRecipientInformation to the correct reci…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T23:37:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b7a2f0482cd2f72a32e2bec7abbd01a171c8714a",
"body": "…ed index entries\n\nReconciles the pkix index baseline against upstream bc-java. Reviewed all 65\nrecorded-vs-upstream mismatches; adopted the self-contained security and\ncorrectness fixes below (deps already present in LTS), left the rest as\nintentional LTS curation, and advanced the index baseline f\n[…]\nnd the ML-DSA digest choice in\nDefaultDigestAlgorithmIdentifierFinder.\n\nVerified: :pkix:test green; japi bcpkix 2.73.11 -> 2.73.12 still 0 removed /\n0 high-severity (all changes are internal/private).",
"is_bot": false,
"headline": "Adopt pkix security/correctness hardenings from upstream; bump review…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T16:33:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e107256b0ffefa0da5a79443298d7fc10424a993",
"body": "…line\n\nPorts the LTS source for these modules up to the current reviewed upstream\nbaseline, preserving LTS curation and customizations. Compat-preserving\ndecisions made while folding in the sync:\n\n- pg: PGPDataEncryptorBuilder.build(byte[],byte[]) (OpenPGP v2 SEIPD / v6\n AEAD) is adopted as a Java \n[…]\nbs in this environment); pg tests green. japi-compliance-checker\n2.73.11 -> 2.73.12 reports 0 removed methods and 0 high-severity problems\nacross bccore/bcprov/bcutil/bcpkix/bctls/bcmail/bcjmail/bcpg.",
"is_bot": false,
"headline": "Sync util/prov/pkix/tls/pg/mail to the reviewed upstream bc-java base…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T16:09:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3784e7724929f691b2d048f124a6ebfd13d9b77e",
"body": "The Java CCMBlockCipher rejects nonce reuse for encryption under the same key\n(RFC 5116 sec. 2.1 / RFC 3610 - reuse means CTR keystream reuse plus a forgeable\nCBC-MAC), but the native path (AESNativeCCM) did not, so CCMTest's\n\"nonce reuse not detected on re-init for encryption\" case failed when the\n\n[…]\n jdk1.9); CCMTest passes on the Java variant;\nmessage/type match the Java guard and the existing native GCM guard. Needs a\nnative-variant test run to confirm end-to-end (native libs unavailable here).",
"is_bot": false,
"headline": "Enforce CCM nonce-reuse guard on the native path",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T15:38:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3c0585ff02c4049dd858fd54f923021e6d1f2c6e",
"body": "The JCE AEAD decrypt stream (JceAEADUtil.PGPAeadInputStream) verified the trailing\nmessage tag only for a short final data chunk. A chunk-aligned message (plaintext\nan exact multiple of chunkLength) ends after a full-size final chunk, whose look-\nahead pre-reads the trailing tag but never verified i\n[…]\ntream is package-private,\nno public API affected.\n\nVerified: pg PGPAeadTest passes (\"Okay\", was \"Jce accepted corrupted final tag\n(n=56, EAX AES-128, v5=true)\"); japi bcpg 0 removed / 0 high-severity.",
"is_bot": false,
"headline": "Verify OpenPGP AEAD final tag on chunk-aligned messages (JCE path)",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T15:05:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "74bb031686d6c471672d94dd9649b426197265a3",
"body": "Adopt the upstream Argon2 S2K parameter validation into PGPUtil.makeKeyFromPassPhrase:\nbefore running the memory-hard Argon2 derivation on attacker-supplied S2K\nparameters, reject a memory-size exponent below the RFC 9106 sec. 3.1 floor\n(m >= 8*p, i.e. exponent >= 3 + bitLen(parallelism - 1)) or abo\n[…]\nase overloads are preserved rather than\nadopted wholesale.\n\nVerified: pg Argon2S2KTest passes (\"Okay\", was failing the memory-floor case);\njapi bcpg 2.73.11->2.73.12 stays 0 removed / 0 high-severity.",
"is_bot": false,
"headline": "Bound Argon2 S2K parameters before key derivation",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T14:52:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b40a3ccd27d2e11180b951f83ebc3ac2bffb5d7f",
"body": "Adopt the upstream builder-layer PBE-iteration DoS guards that reject an\nattacker-declared iteration count read from an untrusted structure before it\ndrives an iterated hash / KDF:\n\n- cert/crmf/PKMACBuilder.setParameters: reject a PBMParameter iteration count\n above the configured ceiling (or Prope\n[…]\n to the pkix\nmodule-info exports (matches upstream). No public API removed.\n\nVerified: prov CRMF AllTests (16) and PfxPduTest (23) pass; japi bcpkix\n2.73.11->2.73.12 stays 0 removed / 0 high-severity.",
"is_bot": false,
"headline": "Bound attacker-supplied PKCS12/CRMF PBE iteration counts",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T14:40:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a4eee9d1a2e26ce9622ea3a19bcd10f1409ad820",
"body": "The GCM ICV-length hardening (RFC 5084, 12..16 octets) added earlier rejects the\n88-bit (11-octet) tag this CMS KEK test builds via new GCMParameters(nonce, 11).\nWrap that single case in a Properties.setThreadOverride(GCM_ALLOW_SHORT_TAGS)\nso it still exercises CMS short-tag handling through the intended opt-in, instead\nof failing at parameter construction. Keeps the hardening; only this test case\nchanges.\n\nVerified: NewEnvelopedDataTest.testAES128KEK passes (was: \"Invalid ICV length: 11\").",
"is_bot": false,
"headline": "Opt NewEnvelopedDataTest short GCM tag into gcm_allow_short_tags",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T14:32:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2298af2b5948759ca008e4f2ee08ae21d257dab7",
"body": "Adopt the upstream util test coverage for parameter validation and OER decode\nlimits, and mark the remaining util test files reviewed:\n\n- asn1/util/test/AllTests, oer/test/AllTests: adopt (register the new tests below).\n- asn1/cms/test/GCMParametersTest, CCMParametersTest: new - exercise the GCM ICV\n[…]\nuites) - index bumped, source unchanged.\n\nVerified: util test suite passes (GCMParametersTest 4, CCMParametersTest 3,\nOERInputStreamLimitTest 2, all 0 failures). No util/core hidden residual surfaced.",
"is_bot": false,
"headline": "Adopt util GCM/CCM/OER parameter hardening test coverage",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T14:17:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cbe98d2e12d3687e7cbf5d8efb60357a7b36c870",
"body": "Adopt the upstream ASN.1 hardening that carries the nested-construction depth\ncounter through lazily-deferred parsing. Previously a LazyEncodedSequence forced\nits content with the StreamUtil depth guard reset each time, so a heavily nested\nDER/BER value parsed lazily (e.g. materialised via hashCode/\n[…]\npted earlier in 27329b37. Verified: that test passes (19/19), asn1\nRegressionTest (51) and crypto RegressionTest (181) remain green, and japi bccore\n2.73.11->2.73.12 stays 0 removed / 0 high-severity.",
"is_bot": false,
"headline": "Enforce ASN.1 nested-construction depth limit on the lazy parse path",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T13:45:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ff40724beaaddce257254f0300ec7a4fa9aeb86a",
"body": "…verged)\n\nBump the index to the current upstream baseline for the 43 prov files that\ndiverge because the LTS edition curates the provider - unshipped PQC providers\n(xmss, ntru, sphincs, sdith, uov, sqisign, ...) and legacy classes registered by\nBouncyCastleProvider, the composite-signature/KEM group\n[…]\nhe\n57 original prov mismatches were adopted separately (private-key hashCode, BcFKS\nand BKS/PKCS12 KDF-iteration bounds, GCM ICV / CCM routing, X.509 policy-tree\nsize). prov index mismatches: 43 -> 0.",
"is_bot": false,
"headline": "Mark remaining prov files reviewed against bc-java baseline (leave-di…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T13:31:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8d14c85b0521778ffc2b7d73e933dd3f68dacf78",
"body": "Adopt the upstream BKS and PKCS12 keystore DoS hardening: iteration counts (and,\nfor BKS, length-prefixed block sizes) read from a not-yet-integrity-checked store\nare bounded before they drive a PBKDF or buffer allocation, preventing a\npre-verification CPU/memory-exhaustion DoS.\n\n- keystore/bc/BcKey\n[…]\njce/PKCS12Util also\nrefreshed to the upstream baseline.\n\nVerified: prov PKCS12StoreTest, KeyStoreTest (BKS) and BCFKSStoreTest all pass;\njapi bcprov 2.73.11->2.73.12 stays 0 removed / 0 high-severity.",
"is_bot": false,
"headline": "Bound attacker-controlled BKS/PKCS12 keystore KDF iteration counts",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T13:24:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8f218b1dcf0ec80aaaef0c7ed2d1765be5df335a",
"body": "Adopt the upstream valid-policy-tree size guard: after each certificate's policy\nprocessing, CertPathValidatorUtilities.checkPolicyTreeSize enforces that the live\nnode count across all depth levels stays within Properties.X509_MAX_POLICY_NODES\n(default 8192), throwing CertPathValidatorException othe\n[…]\nssCertD calls it once per certificate.\n\nOnly the policy-tree bound was taken (not the unrelated legacy org.bouncycastle.x509\n/ CRLDP changes in upstream CertPathValidatorUtilities). japi bcprov 0/0/0.",
"is_bot": false,
"headline": "Bound X.509 valid-policy-tree size (CVE-2023-0464 class DoS)",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T13:16:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cd86d01b3056a90b1eb142130634e764d9695c30",
"body": "Adopt the upstream GCMParameters ICV-length validation: a parsed\naes-ICVlen (or a constructed one) must be 12..16 octets per RFC 5084, relaxing\nto the NIST SP 800-38D 4-octet minimum only when\norg.bouncycastle.jca.gcm_allow_short_tags is set; the SEQUENCE size is also\nbounded. This rejects malformed\n[…]\n refactor.\n\nVerified: GCMParameters accepts 12/13/16 and rejects 8/17; AES/GCM and AES/CCM\nboth round-trip through AlgorithmParameters via the provider. japi bccore/bcprov\n0 removed / 0 high-severity.",
"is_bot": false,
"headline": "Enforce GCM ICV length and route CCM AEAD params correctly",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T13:16:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e099011dc4d4410ad6d4fb757f02703b37382b1c",
"body": "Harden BcFKSKeyStoreSpi.generateKey against a pre-integrity-check DoS: the scrypt\ncost/block-size and PBKDF2 iteration count that drive the store-MAC key\nderivation come from the not-yet-verified keystore, so validate them before the\nexpensive derivation.\n\n- validateScryptParams: reject null/non-pos\n[…]\neptions refactor), so no public API is\nadded or removed. Adopt the upstream BCFKSStoreTest which exercises the rejection.\nVerified: prov BCFKSStoreTest passes (\"BCFKS: Okay\"); japi bcprov stays 0/0/0.",
"is_bot": false,
"headline": "Bound attacker-controlled BCFKS KDF cost params before verification",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T12:36:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6dbc3b3b573b6ddabc582938e66db03bb418acc4",
"body": "Adopt the upstream PrivateKeyHashUtil helper and route the DH/DSA/ElGamal/GOST3410\nJCE private-key classes' hashCode() through it. Instead of mixing the secret\nvalue x into the hash, the helper derives the corresponding public value\n(y = g^x mod p) and hashes that together with the domain parameters\n[…]\nserves equals()/hashCode() and distinct keys stay unequal. japi: bcprov\n2.73.11->2.73.12 remains 0 removed / 0 high-severity. Index bumped for the five\nadopted classes; entry added for the new helper.",
"is_bot": false,
"headline": "Adopt private-key hashCode hardening (PrivateKeyHashUtil)",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T12:28:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c52316845e22b1339dd67b814125d5f98ea72acf",
"body": "Extend the indexes/ section of CLAUDE.md with what the reconciliation against\nupstream bc-java requires in practice:\n- the check-indexes.sh / index-update.sh scripts, the core->util asn1 OID remap\n (and that iana is excluded), and the review/baseline policy (bump an index only\n once the file is re\n[…]\nt modules/tests (and running the KAT/regression suites) reveals it.\n- the prov compileJava17Java / javax.crypto.KEM multi-release build detail.\n\nNo project skills exist in the repo, so none to update.",
"is_bot": false,
"headline": "Document index reconciliation workflow and hidden stale-source residuals",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T11:29:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "50d3a63fd904fb449628d71fd678848a2d8d6b8d",
"body": "…o.KEM\n\nCompletes the in-progress migration of prov's multi-release layer from JDK 21 to\nJDK 17 (source set, META-INF/versions, and per-JDK test tasks renamed java21 ->\njava17). The ML-KEM JCE SPIs under src/main/jdk17 use javax.crypto.KEM (JEP 452,\nJDK 21, backported to Java 17 at runtime); compili\n[…]\nE tests pass standalone - MLKEMTest (14) and MLKEMKeyPairGeneratorTest\n(4). The test-source sweep across util/prov/pkix/tls/pg/mail surfaced no other\nresiduals; this build config was the only blocker.",
"is_bot": false,
"headline": "Compile prov jdk17 ML-KEM JCE SPIs against the backported javax.crypt…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T11:29:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b123a3044ec8b0adc487e3740b70b1cbe01cf46b",
"body": null,
"is_bot": false,
"headline": "backwards compat api fix",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T11:16:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1a491a1c28d9d04218d9be684cba6e9cf7d496c3",
"body": null,
"is_bot": false,
"headline": "smime updates",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T11:07:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "471ce0ce85925351c7fabe38a29759405d2baa7d",
"body": "These test sources are intentionally diverged because the LTS edition ships a\nsubset of algorithms/APIs; bump their index to the current upstream baseline so\nfuture upstream changes are flagged, with no source change:\n\n- crypto/test/RegressionTest: LTS-curated list (upstream references ~17 tests for\n[…]\ne, X509Extensions, ...).\n- asn1/test/QCStatementUnitTest: upstream uses QcType, not shipped.\n- crypto/test/AsymmetricConstraintsTest: upstream uses ECDHRawAgreement /\n ECMQVRawAgreement, not shipped.",
"is_bot": false,
"headline": "Mark curated LTS test suites reviewed against bc-java baseline",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T10:54:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "27329b374af9e8195ba2f08f46eced538299f705",
"body": "Adopt current bc-java test sources that were stale/curated residuals:\n- util/utiltest: adopt AllTests and add StreamsTest (covers the newly-adopted\n Streams.readLenBytesFully) and AggregateRuntimeExceptionTest (covers the new\n util.AggregateRuntimeException class).\n- asn1/test/ASN1SequenceParserTe\n[…]\no/test/SimpleTestTest: adopt the upstream runner refactor.\n\nVerified: util utiltest AllTests passes (24 tests), asn1 RegressionTest passes,\nSimpleTestTest runs the crypto RegressionTest suite cleanly.",
"is_bot": false,
"headline": "Adopt upstream util and asn1 test coverage",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T10:54:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f5bb8c95523498dd3fdc89b333aa3e8afeea5b5c",
"body": "Adopt the upstream LMSPublicKeyParameters and HSSPublicKeyParameters parse paths,\nwhich reject unknown LMS/LM-OTS type codes, out-of-range HSS level counts, and\ntrailing data with a clean failure instead of throwing NullPointerException on a\nnull looked-up parameter. Also adopt the upstream lms AllT\n[…]\nsts, which exercise these negative cases.\n\nBoth parameter classes were stale-source residuals (index already at the upstream\nhash); no public methods removed. Verified: lms AllTests passes (24 tests).",
"is_bot": false,
"headline": "Harden LMS/HSS public-key parsing to reject malformed keys",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T10:54:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "26e5bd50c9a534be67e00dafe00429b48830dc54",
"body": null,
"is_bot": false,
"headline": "pem header checking",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T10:52:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6ec34f128e93ff8a97fc54e12baa4fd716654c86",
"body": "Reviewed: the divergence from upstream is deliberate and carries no substantive\nchange to adopt. LTS declares DefaultBufferedBlockCipher as\n\"implements BufferedBlockCipher\" (BufferedBlockCipher is an interface in LTS so\nnative block ciphers can implement it) where upstream \"extends\" a concrete\nclass\n[…]\ns vs @exception) and an arithmetically identical blockCount expression.\nBump the index to the current upstream baseline so future upstream changes are\nflagged; the source intentionally stays diverged.",
"is_bot": false,
"headline": "Mark DefaultBufferedBlockCipher reviewed against bc-java baseline",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T10:42:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "284df651ba63860f51bba62e193e736f5e6a3976",
"body": "The upstream BigIntegers.createRandomPrime (adopted earlier) always rejects\ncandidates with small factors, so it no longer returns tiny primes; the old\nLTS-only test cases asserting createRandomPrime(3, ...) == 5 and\ncreateRandomPrime(10, ...) == 743 (which relied on the removed MAX_SMALL\nspecial-ca\n[…]\nhrow. Adopt the current\nupstream test, which drops those cases.\n\nThis test was a stale-source residual (index already at the upstream hash);\nsurfaced by running crypto RegressionTest, now green again.",
"is_bot": false,
"headline": "Align crypto BigIntegersTest with the adopted createRandomPrime",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T10:42:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "41eace62438749587c03a19e524f6f9bd062074f",
"body": "Adopt the bc-java refactor that keeps the ECDH-C unified secret in field-element\nform instead of round-tripping through BigInteger:\n\n- crypto/agreement/ECDHCBasicAgreement: extract a package-private\n calculateAgreementFieldElement(...) returning the shared X coordinate as an\n ECFieldElement; the p\n[…]\ning the BigInteger/asUnsignedByteArray step.\n\nBehaviour-preserving; ECDHCBasicAgreement was another stale-source residual.\nVerified: crypto RegressionTest passes (incl. ECTest ECDH-C unified vectors).",
"is_bot": false,
"headline": "Adopt upstream ECDH-C constant-time agreement refactor",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T10:42:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6893ee9f093e0b4eec5e392a27056380b7af398f",
"body": "Adopt the bc-java reviewStructure diagnostic feature (github #1508): a\ncollect-all-problems parse mode for tbsCertificate / extensions used by the\nX509CertificateReviewer tooling, alongside the strict getInstance path.\n\n- asn1/x509/TBSCertificate, asn1/x509/Extensions: adopt current upstream. The\n \n[…]\n (index already at the upstream\nhash). Verified: core compiles and the asn1 RegressionTest passes (51/51,\nincl. CertificateTest). Index bumped for the two adopted files; entry added for\nthe new class.",
"is_bot": false,
"headline": "Adopt upstream cert-structure review feature (TBSCertificate/Extensions)",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T10:32:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "618ba1f6052485bd6b336241b2f51da6b1b059a7",
"body": "Two more stale-source residuals of the earlier checkout incident: the index\nalready recorded the current bc-java hash for both files while the committed\nsource lagged behind, so check-indexes could not see the drift. Surfaced by\ncompiling pkix and pg against core.\n\n- crypto/params/RSAKeyParameters: \n[…]\nFully(InputStream, int)\n used by pg gpg SExpression.\n\nVerified: crypto RSATest KAT passes (\"RSA: Okay\") and all eight modules\n(core, prov, util, pkix, tls, pg, mail, jmail) compile main source clean.",
"is_bot": false,
"headline": "Restore stale RSAKeyParameters and Streams to the upstream baseline",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T10:23:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4f9c271d8e1b51099d640c295097a0e6b7c4c434",
"body": "Adopt the current bc-java baseline for asn1/gm/GMObjectIdentifiers: add the\nGM/T 0010-2012 SM2 cryptography application content-type OIDs under\n1.2.156.10197.6.1.4.2 (sm2_pkcs7 and its data / signedData / envelopedData /\nsignedAndEnvelopedData / encryptedData / keyAgreementInfoData branches).\nPurely\n[…]\ne earlier checkout incident (index already\nat the upstream hash, source missing the constants) - surfaced by compiling the\nprov module against core. Update bc-java.core.index to the upstream baseline.",
"is_bot": false,
"headline": "Add SM2 PKCS#7 content-type OIDs to GMObjectIdentifiers",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T10:16:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d3d7b19c7c7ea862b410f499d1bab1af814ce355",
"body": "Sync core util BigIntegers to the current bc-java baseline. Adds the\nconstant-time areSecretValuesEqual(int, BigInteger, BigInteger) used by the\nprov private-key equals() implementations (RSA/DSA/DH/EC/GOST secret-value\ncomparison), adds hasAnySmallFactors and rewrites createRandomPrime to use it,\na\n[…]\ne compiles,\nareSecretValuesEqual (equal / unequal / high-bit) correct, createRandomPrime\nstill yields probable primes at the requested bit length, *ValueExact round-trip\nand overflow rejection intact.",
"is_bot": false,
"headline": "Adopt upstream BigIntegers (areSecretValuesEqual, hasAnySmallFactors)",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T10:14:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8685574b612e3ced60d06f74187a7a568c71f243",
"body": "…udit)\n\nPort the upstream bc-java \"byte-identical performance refactor, PolyVecK/L ->\nPolyVec merge, and constant-time audit\" for crypto/signers/mldsa: merge the two\npackage-private dimension-specific vector classes (PolyVecK, PolyVecL) into a\nsingle PolyVec, and adopt the accompanying MLDSAEngine, \n[…]\nion succeeds, and tampered signatures / wrong\nmessages are rejected. Signature lengths 2420/3309/4627 per FIPS 204.\n\nUpdate bc-java.core.index to the current upstream baseline for the 7 adopted files.",
"is_bot": false,
"headline": "Adopt upstream ML-DSA PolyVecK/L -> PolyVec refactor (constant-time a…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T10:10:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "574e31ce1d402ce4436f571fa4c6ba86b03fb288",
"body": "Set bc-java.core.index to the current bc-java hashes for files reviewed this session\n(ASN.1/util/modes/engines merges + the reviewed PQC helper cluster), so check-indexes\nno longer flags them. Remaining core mismatches: 19 (genuinely un-reviewed).",
"is_bot": false,
"headline": "Check off reviewed core files against bc-java baseline (index-update.sh)",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T09:54:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c66fc68eabecd0487ff2f0aad54eb96b96940adf",
"body": "…te.sh\n\nUpstream relocated org.bouncycastle.asn1.iana from the util module back to core, so the\ncore->util remap no longer applies to it. Both scripts now compare/record the iana files\nagainst upstream core (matching their actual location) instead of the nonexistent util path.",
"is_bot": false,
"headline": "Drop iana from asn1 core->util remap in check-indexes.sh / index-upda…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T09:42:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "679acce016428c612a401694c90ad22dce1cfcfc",
"body": "… gate)\n\nRestore incident-reverted sources to current bc-java so the non-DER-time feature works\nend to end:\n- ASN1GeneralizedTime/ASN1UTCTime: strict parse-time structural validation (rejects\n malformed time values, e.g. 2-digit-year GeneralizedTime, github #2040).\n- ASN1OutputStream/DEROutputStrea\n[…]\nement as an IOException.\n- Add AllowNonDerTimeTest and wire it into asn1 RegressionTest; index its entry.\n\nVerified: asn1.test.RegressionTest 51/51, crypto.test.RegressionTest 181/181 (no regression).",
"is_bot": false,
"headline": "Complete ASN.1 non-DER-time enforcement (parse validation + DER-write…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T09:32:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0dd94681f1aee01a5ffe711d6aab1937822faebe",
"body": "…gressionTest green)\n\nThe incident had reverted these test sources to stale baselines while their index stayed\nat current bc-java. Re-adopt upstream CCMTest, EAXTest, OCBTest, DSTU7624Test,\nCipherStreamTest and AEADTestUtil so they match the merged mode behavior (nonce-reuse\nguards; KCCM plaintext-only decrypt output). crypto.test.RegressionTest now passes 181/181.",
"is_bot": false,
"headline": "Restore crypto mode test suites to match merged AEAD modes (crypto Re…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T09:29:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cf5d1795a7a8cbdc1e2de92cb000f3badbe5862e",
"body": "ML-KEM is a shipped LTS algorithm, but its private-key parsing block in\npqc/crypto/util/PrivateKeyFactory was commented out, so ML-KEM PrivateKeyInfo could not\nbe decoded via this factory. Activate the block (matches upstream: RFC 9881 seed/expanded\nhandling with the seed-consistency check). All req\n[…]\nry remains intentionally diverged (LTS ships only\nlms/mldsa/mlkem/slhdsa; the other ~22 upstream PQC algorithms stay excluded), so it stays\nflagged by check-indexes for future shared-algorithm review.",
"is_bot": false,
"headline": "Enable ML-KEM private-key parsing in pqc PrivateKeyFactory",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T08:35:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "972418ec4134dafb9ef502be4d214e0ee8668472",
"body": "Adopt upstream's table/SWAR round-transform optimizations (byte-identical by construction,\nCT-neutral per upstream notes) for both engines; re-add LTS's `implements ECBModeCipher`.\nUpdate bc-java.core.index hashes.",
"is_bot": false,
"headline": "Merge upstream ARIAEngine and GOST3412_2015Engine performance refactors",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T08:17:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "472d011746d40ee57b60a1f207efb86f39c9b604",
"body": "…ative path)\n\n- SkeinEngine: adopt upstream outputSizeBytes * 8L (avoid int overflow for large output\n sizes); keep LTS's public inner-class members (no visibility reduction).\n- AESEngine: reviewed against upstream - only cosmetic upstream changes (a comment and a\n WorkingKey rename); keep LTS native dispatch (AESNativeEngine), ECBModeCipher, and\n AES[Java] toString. Index bumped to current bc-java baseline.",
"is_bot": false,
"headline": "Merge SkeinEngine overflow fix; reconcile AESEngine index (keep LTS n…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T08:15:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "93ea507b64c9528a8d0e6526eb47f949cd565d56",
"body": "- Salsa20Engine: adopt upstream (fixes counter-carry to a proper unsigned comparison;\n adds deprecated sigma/tau constants). No LTS-specific divergence.\n- CamelliaLightEngine: adopt upstream (uses Bytes.rotateLeft in place of local lRot8);\n re-add LTS's `implements ECBModeCipher`.\n- Update bc-java.core.index hashes.",
"is_bot": false,
"headline": "Merge upstream Salsa20Engine and CamelliaLightEngine",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T08:13:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7721e3b8b5c90c6836df2f18ae48a6ce1ae9fe09",
"body": "…param validation)\n\nAdopt upstream DSTU7624 CCM version (correct trailing partial-block CBC-MAC/CTR handling,\nRFC 5116 nonce-reuse detection, ParametersWithIV validation, partial-block interop caveat\nin javadoc). Preserve LTS's public ExposedByteArrayOutputStream methods. Update index hash.",
"is_bot": false,
"headline": "Merge upstream KCCMBlockCipher (partial-block handling, nonce guard, …",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T08:10:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "50203467123f6369eb19b5843d7c0314dbfff37f",
"body": "…ypt, nonce guard)\n\nAdopt upstream DSTU7624 GCM fixes: correct trailing partial-block AAD/payload handling,\nverify the tag before writing decrypted plaintext, RFC-style nonce-reuse detection, and\nconstant-time key comparison. Preserve LTS's DefaultBufferedBlockCipher (BufferedBlockCipher\nis an interface in LTS) and public ExposedByteArrayOutputStream methods. Update index hash.",
"is_bot": false,
"headline": "Merge upstream KGCMBlockCipher (partial-block, tag-verify-before-decr…",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T08:08:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3afc95332dea49e99f4289ff8713c07dbb0898f2",
"body": "…guard), keep LTS native path\n\nAdopt upstream: decrypt into a private buffer and verify the CBC-MAC before writing any\nplaintext to the caller's output (NIST SP 800-38C 6.2 - do not reveal unverified plaintext\non tag failure), plus RFC 5116 nonce-reuse detection for encryption. Preserve LTS native\ndispatch (createCCM), CCM[Java] toString, and public ExposedByteArrayOutputStream methods.\nUpdate bc-java.core.index hash.",
"is_bot": false,
"headline": "Merge upstream CCMBlockCipher (MAC-verify-before-write + nonce-reuse …",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T08:05:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "870f318d58b9f2f03837dd5f3dbda24c12770044",
"body": "Adopt upstream constant-time key comparison (nonce-reuse check) and ParametersWithIV\nvalidation. Preserve LTS-specific native dispatch (createGCM), GCM[Java] toString, and\nthe 12-byte minimum IV requirement. Update bc-java.core.index hash.",
"is_bot": false,
"headline": "Merge upstream GCMBlockCipher hardenings, preserving LTS native path",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T08:02:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "81d41b890b919e4b150cf1accb52f1418e4dc936",
"body": "Adopt upstream EAXBlockCipher (RFC 5116 nonce-reuse detection for encryption,\ngetMacSize validation), re-adding LTS's `implements EAXModeCipher` marker interface.\nUpdate bc-java.core.index hash.",
"is_bot": false,
"headline": "Merge upstream EAXBlockCipher (nonce-reuse guard + MAC-size validation)",
"author_name": "David Hook",
"author_login": "dghgit",
"committed_at": "2026-07-13T07:55:46Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 0,
"commits_last_year": 237,
"latest_release_at": null,
"latest_release_tag": null,
"releases_from_tags": false,
"days_since_last_push": 8,
"active_weeks_last_year": 12,
"days_since_latest_release": null,
"mean_days_between_releases": null
},
"community": {
"has_readme": true,
"has_license": false,
"has_description": true,
"has_contributing": false,
"health_percentage": 37,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": []
},
"popularity": {
"forks": 13,
"stars": 26,
"watchers": 2,
"fork_history": {
"days": [
{
"date": "2023-10-19",
"count": 1
},
{
"date": "2024-03-19",
"count": 1
},
{
"date": "2024-06-12",
"count": 1
},
{
"date": "2024-10-30",
"count": 1
},
{
"date": "2024-11-21",
"count": 1
},
{
"date": "2024-11-22",
"count": 1
},
{
"date": "2025-01-02",
"count": 1
},
{
"date": "2025-06-15",
"count": 1
},
{
"date": "2025-07-06",
"count": 1
},
{
"date": "2025-09-12",
"count": 1
},
{
"date": "2025-12-30",
"count": 1
},
{
"date": "2026-01-10",
"count": 1
},
{
"date": "2026-02-26",
"count": 1
}
],
"complete": true,
"collected": 13,
"total_forks": 13
},
"star_history": null,
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"example",
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"bctools/build.gradle",
"benchmark/build.gradle",
"benchmark_new/build.gradle",
"bom/build.gradle",
"build.gradle",
"core/build.gradle",
"jmail/build.gradle",
"mail/build.gradle",
"pg/build.gradle",
"pkix/build.gradle",
"prov/build.gradle",
"test/build.gradle",
"tls/build.gradle",
"util/build.gradle"
],
"largest_source_bytes": 525816,
"source_files_sampled": 5311,
"oversized_source_files": 50,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 29937
},
"dependencies": {
"manifests": [
"bctools/build.gradle",
"benchmark/build.gradle",
"benchmark_new/build.gradle",
"bom/build.gradle",
"build.gradle",
"core/build.gradle",
"jmail/build.gradle",
"mail/build.gradle",
"pg/build.gradle",
"pkix/build.gradle",
"prov/build.gradle",
"test/build.gradle",
"tls/build.gradle",
"util/build.gradle"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"maven"
],
"dependencies": [],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 0,
"open_issues": 0,
"closed_ratio": 1,
"closed_issues": 8,
"closed_unmerged_prs": 1
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "dghgit",
"commits": 694,
"avatar_url": "https://avatars.githubusercontent.com/u/10509846?v=4"
},
{
"type": "User",
"login": "mwcw",
"commits": 515,
"avatar_url": "https://avatars.githubusercontent.com/u/30947532?v=4"
},
{
"type": "User",
"login": "ligefeiBouncycastle",
"commits": 97,
"avatar_url": "https://avatars.githubusercontent.com/u/143379185?v=4"
},
{
"type": "User",
"login": "meganwoods",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/4627862?v=4"
}
],
"contributors_sampled": 4,
"top_contributor_share": 0.531
},
"quality_signals": {
"has_ci": false,
"has_tests": true,
"ci_workflows": [],
"has_docs_dir": false,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 0,
"reason": "binaries present in source code",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 3 contributing companies or organizations -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": null,
"reason": "no workflows found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 0,
"reason": "license file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": null,
"reason": "no dependencies found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": null,
"reason": "No tokens found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "053e59f6a16a66b1f83030ab06643f8507c49d39",
"ran_at": "2026-07-25T10:06:12Z",
"aggregate_score": 2.6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": null,
"oldest_open_prs": [],
"last_merged_pr_at": null,
"ci_last_conclusion": null,
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/bcgit/bc-lts-java",
"host": "github.com",
"name": "bc-lts-java",
"owner": "bcgit"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": null,
"notes": [],
"value": 37,
"inputs": {
"security": 26,
"vitality": 39,
"community": 29,
"governance": 49,
"engineering": 38
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "at_risk",
"name": "Vitality",
"value": 39,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"commits_last_year": 237,
"human_commit_share": 1,
"days_since_last_push": 8,
"active_weeks_last_year": 12
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 8 days ago",
"points": 28.8,
"status": "partial",
"details": [
{
"code": "push_recency",
"params": {
"days": 8
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "12/52 weeks with commits",
"points": 8.3,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 12
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "237 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 237
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "critical",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 1,
"inputs": {
"releases_count": 0
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "no releases published",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_releases_published",
"params": {}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "no releases",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_releases",
"params": {}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "no releases",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_releases",
"params": {}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 8,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 8 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 8
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "critical",
"name": "Community & Adoption",
"value": 29,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 32,
"inputs": {
"forks": 13,
"stars": 26,
"watchers": 2,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "26 stars",
"points": 22.7,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 26
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "13 forks",
"points": 9,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 13
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "2 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 2
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "critical",
"name": "Community health",
"note": null,
"notes": [],
"value": 25,
"inputs": {
"has_readme": true,
"has_license": false,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "no license file detected",
"points": 0,
"status": "missed",
"details": [
{
"code": "license_absent",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 49,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 35,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 4,
"top_contributor_share": 0.531
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 53% of commits",
"points": 10.6,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 53
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "4 contributors",
"points": 5.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 4
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 3 contributing companies or organizations -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "at_risk",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 47,
"inputs": {
"merged_prs": 0,
"open_issues": 0,
"closed_issues": 8,
"issue_closed_ratio": 1,
"closed_unmerged_prs": 1
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "100% of issues closed",
"points": 46.8,
"status": "met",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 100
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "0/1 decided PRs merged",
"points": 0,
"status": "missed",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 0,
"decided": 1
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 67,
"inputs": {
"followers": 296,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "bcgit",
"public_repos": 9,
"account_age_days": 4804
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "296 followers of bcgit",
"points": 17.8,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 296,
"login": "bcgit"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "9 public repos, account ~13 yr old",
"points": 19.3,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 9
}
},
{
"code": "account_age_years",
"params": {
"years": 13
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "at_risk",
"name": "Engineering Quality",
"value": 38,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "at_risk",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 30,
"inputs": {
"has_ci": false,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "critical",
"name": "Security",
"value": 26,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "critical",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"dangerous_workflow",
"packaging",
"pinned_dependencies",
"signed_releases",
"token_permissions"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 26,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 12,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 6,
"scorecard_aggregate": 2.6
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "binaries present in source code",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 3 contributing companies or organizations -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no workflows found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "no dependencies found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "No tokens found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 4
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 67,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.83,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 29937
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "83 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 83,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_pinned_dependencies"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 51,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"bctools/build.gradle",
"benchmark/build.gradle",
"benchmark_new/build.gradle",
"bom/build.gradle",
"build.gradle",
"core/build.gradle",
"jmail/build.gradle",
"mail/build.gradle",
"pg/build.gradle",
"pkix/build.gradle",
"prov/build.gradle",
"test/build.gradle",
"tls/build.gradle",
"util/build.gradle"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "bctools/build.gradle, benchmark/build.gradle, benchmark_new/build.gradle (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "bctools/build.gradle, benchmark/build.gradle, benchmark_new/build.gradle"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Java (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Java"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "no dependencies found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Java",
"largest_source_bytes": 525816,
"source_files_sampled": 5311,
"oversized_source_files": 50
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Java (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Java"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "50/5311 source files over 60KB",
"points": 54.5,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 5311,
"oversized": 50
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"example",
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "example, examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "example, examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-25T10:06:24.772154Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/b/bcgit/bc-lts-java.svg",
"full_name": "bcgit/bc-lts-java",
"license_state": "absent",
"license_spdx": null
}