Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
bcgit
/
bc-java
Public mirror
mirrored from
https://www.bouncycastle.org/repositories/bc-java
Notifications
You must be signed in to change notification settings
Fork
1.3k
Star
2.7k
Code
Issues
57
Pull requests
34
Discussions
Actions
Projects
Wiki
Security and quality
0
Insights
Additional navigation options
Code
Issues
Pull requests
Discussions
Actions
Projects
Wiki
Security and quality
Insights
Commits
Branch selector
main
User selector
dghgit
Datepicker
All time
Commit history
Commits on Sep 25, 2026
Merge branch 'main' of gitlab.cryptoworkshop.com:root/bc-java
dghgit
committed
0a65497
View commit details
Copy full SHA for 0a65497
Browse repository at this point
conventions.md: CVE numbers stay out of release notes, commits and comments until the fixing version is released.
dghgit
committed
46f61c2
View commit details
Copy full SHA for 46f61c2
Browse repository at this point
The PBES1 and PKCS#12 PBE providers now bound the iteration count they parse and derive with under org.bouncycastle.pbe.max_iteration_count, as PBKDF2 does.
dghgit
committed
4044aea
View commit details
Copy full SHA for 4044aea
Browse repository at this point
CMS 1-Pass ECMQV now feeds the KDF the DER-encoded ECC-CMS-SharedInfo per RFC 5753, with the raw-ukm retry for earlier BC messages gated by org.bouncycastle.cms.allow_legacy_keyagree_kdf.
dghgit
committed
bad4f4e
View commit details
Copy full SHA for bad4f4e
Browse repository at this point
Corrected the SecurityExceptions factory list in conventions.md: the jdk1.3 overlay is no longer a factory behind.
dghgit
committed
c65e133
View commit details
Copy full SHA for c65e133
Browse repository at this point
ML-KEM KeyGenerator, Cipher, KEM and KeyFactory.translateKey now convert ML-KEM keys from other providers via their encodings, with TLS tests for keys supplied ahead of BC, relates to github #2466.
dghgit
committed
be03eae
View commit details
Copy full SHA for be03eae
Browse repository at this point
Commits on Sep 24, 2026
Merge branch 'main' of gitlab.cryptoworkshop.com:root/bc-java
dghgit
committed
5bb898c
View commit details
Copy full SHA for 5bb898c
Browse repository at this point
DSTU 7624: KGCM re-init starts from a clean state and resets on failure, KCCM validates the MAC size against the block and takes the G1 length from processPacket's argument, over-long nonces are re…
Show description for bd7be9c
dghgit
committed
bd7be9c
View commit details
Copy full SHA for bd7be9c
Browse repository at this point
CertPathBuilder: count only non-self-issued intermediates against the maximum path length, and carry the caller's maximum path length and excluded certificates into the indirect CRL signer's path b…
Show description for 8e2752c
dghgit
committed
8e2752c
View commit details
Copy full SHA for 8e2752c
Browse repository at this point
DSTU 7624: KGCM/KGMac reject empty associated text with empty data, and DSTU7624Mac rejects an empty message, as DSTU 7624:2014 sec. 12.1 and sec. 9.1 require.
dghgit
committed
004f0ba
View commit details
Copy full SHA for 004f0ba
Browse repository at this point
date validity fuzz report
dghgit
committed
5fb96af
View commit details
Copy full SHA for 5fb96af
Browse repository at this point
Commits on Sep 23, 2026
Merge branch 'main' of gitlab.cryptoworkshop.com:root/bc-java
dghgit
committed
15f9eb5
View commit details
Copy full SHA for 15f9eb5
Browse repository at this point
Synced the JKS keystore fixture into the jdk1.4 PKCS12StoreTest overlay, which the JKS and BCFKS store tests compile against.
dghgit
committed
28fb6c7
View commit details
Copy full SHA for 28fb6c7
Browse repository at this point
Added the cast the jdk1.4 build's generic stripping requires on the signer iterator in CompositeMLDSASignedDataTest.
dghgit
committed
2bf9e70
View commit details
Copy full SHA for 2bf9e70
Browse repository at this point
ASN.1: check the day of a UTCTime or GeneralizedTime against the length of the month it names, so a date the calendar would roll into the next month is rejected on read, with org.bouncycastle.asn1.…
Show description for 3d311d8
dghgit
committed
3d311d8
View commit details
Copy full SHA for 3d311d8
Browse repository at this point
CMS: derive the RFC 5990 RSA-KTS key to the length the data encapsulation mechanism's key-wrapping algorithm fixes, and refuse a keyLength which disagrees with it before deriving anything.
dghgit
committed
7cadc88
View commit details
Copy full SHA for 7cadc88
Browse repository at this point
KeyAgreement: report an initialisation the unified and VKO agreements cannot carry out as the parameter error the JCA declares rather than as an unchecked exception, and apply the RFC 7836 default …
Show description for 033fe35
dghgit
committed
033fe35
View commit details
Copy full SHA for 033fe35
Browse repository at this point
XMSS: move the XMSS and XMSS^MT JCE bindings to org.bouncycastle.jcajce.provider.asymmetric.xmss, promote the key interfaces to org.bouncycastle.jcajce.interfaces and the parameter specs to org.bou…
Show description for 1121e2b
dghgit
committed
1121e2b
View commit details
Copy full SHA for 1121e2b
Browse repository at this point
LMS: move the JCE bindings to org.bouncycastle.jcajce.provider.asymmetric.lms, promote the key interfaces to org.bouncycastle.jcajce.interfaces and the key generation parameter specs to org.bouncyc…
Show description for 7133aa6
dghgit
committed
7133aa6
View commit details
Copy full SHA for 7133aa6
Browse repository at this point
Compute the TupleHash element length prefix in long arithmetic and refuse a negative length in left_encode / right_encode, relates to github PR #2462.
dghgit
committed
db49249
View commit details
Copy full SHA for db49249
Browse repository at this point
PKIX: apply the RFC 5280 sec. 6.3.3 (b)(2)(i) distribution point name match and the (d) reasons intersection when either PKIXCertPathReviewer picks a CRL, and report an exception rather than a null…
Show description for 9c0b4db
dghgit
committed
9c0b4db
View commit details
Copy full SHA for 9c0b4db
Browse repository at this point
Commits on Sep 22, 2026
OpenPGP: add PGPEncryptedDataList.extractSessionKeyEncryptedData(boolean) so a session key the caller recovered from a password is quick checked again, and use it on the high-level API's passphrase…
Show description for c576fe9
dghgit
committed
c576fe9
View commit details
Copy full SHA for c576fe9
Browse repository at this point
SM9: Cipher.SM9 decrypts in the mode it was configured with rather than the one the ciphertext's enType names, and neither data-encapsulation mode now produces or accepts a 16-byte C2.
dghgit
committed
94270ff
View commit details
Copy full SHA for 94270ff
Browse repository at this point
PKCS12: generate the MAC key derivation salt for every write rather than keeping the one a loaded file carried, floor an inherited PBMAC1 PBKDF2 count at org.bouncycastle.pkcs12.pbkdf2_it_count, an…
Show description for 04e1bf3
dghgit
committed
04e1bf3
View commit details
Copy full SHA for 04e1bf3
Browse repository at this point
Argon2: the generator zeroises each block before returning it to the BlockPool, so a custom pool neither has to clear nor can observe password-derived data, and getBlockCount() gives the number of …
Show description for 42773ea
dghgit
committed
42773ea
View commit details
Copy full SHA for 42773ea
Browse repository at this point
Merge branch 'main' of gitlab.cryptoworkshop.com:root/bc-java
Show description for c71f93e
dghgit
committed
c71f93e
View commit details
Copy full SHA for c71f93e
Browse repository at this point
CMS: pass the user keying material to HKDF as the salt as well as in the ECC-CMS-SharedInfo entityUInfo for the RFC 8418 key agreement schemes, as sec. 2.2 requires, relates to github #2454.
dghgit
committed
fcb5a4a
View commit details
Copy full SHA for fcb5a4a
Browse repository at this point
CRMF: add the RFC 4211 pkiPublicationInfo and oldCertID controls, a getControlValue() that reads the raw value of any control present, and JCA conveniences for the protocolEncrKey and oldCertID con…
Show description for c90d820
dghgit
committed
c90d820
View commit details
Copy full SHA for c90d820
Browse repository at this point
CRMF: reject the publication information RFC 4211 sec. 6.3 forbids - pubInfos present with the dontPublish action, or present and empty - on parsing and on construction.
dghgit
committed
dc6822a
View commit details
Copy full SHA for dc6822a
Browse repository at this point
pgsc: OpenPGPSmartCard.requireUserPin returns a clone, so the card operations' finally blocks clear a PIN of their own rather than the array the KeyPassphraseProvider still owns, and the smart-card…
Show description for 3261313
dghgit
committed
3261313
View commit details
Copy full SHA for 3261313
Browse repository at this point
pg: machine-enforce that org.bouncycastle.openpgp.operator does not import org.bouncycastle.openpgp.api, the dependency running api to operator and not back.
dghgit
committed
19b659d
View commit details
Copy full SHA for 19b659d
Browse repository at this point
pg: say in the javadoc of OpenPGPKeyGenerator.build(char[]) that it zeroizes the array it is passed, the one place in the API that clears a caller's.
dghgit
committed
b70137e
View commit details
Copy full SHA for b70137e
Browse repository at this point
CMS: resolve the RFC 9709 key-derivation wrapper in one place per package, reporting an absent or unreadable content-encryption algorithm as the CMSException the callers declare.
dghgit
committed
d47c0a3
View commit details
Copy full SHA for d47c0a3
Browse repository at this point
Grain-128AEAD: report an output buffer too short for a processBytes() or processByte() call as an OutputLengthException, as the general AEAD path does, rather than letting the write run off the end.
dghgit
committed
8b92def
View commit details
Copy full SHA for 8b92def
Browse repository at this point
docs/claude: note that the jdk1.4 preprocessor's generic stripping leaves a generic interface implemented with the type argument's signature overriding nothing.
dghgit
committed
58de282
View commit details
Copy full SHA for 58de282
Browse repository at this point
Previous
Next
You can’t perform that action at this time.