Skip to content

Add PQC Migration Readiness to Code Analysis - #1347

Open
Arpan0995 wants to merge 1 commit into
akullpp:mainfrom
Arpan0995:add-pqc-migration-readiness
Open

Arpan0995 wants to merge 1 commit into
akullpp:mainfrom
Arpan0995:add-pqc-migration-readiness

Conversation

@Arpan0995

@Arpan0995 Arpan0995 commented Oct 5, 2026 •

Copy link
Copy Markdown

Suggestion type

  • Project
  • Resource

Adds PQC Migration Readiness under Code Analysis in README_SOURCE.md.

It is a static analyzer for Java source that finds quantum-vulnerable cryptography (RSA, ECDSA and (EC)DH through the JCA) and scores how hard each site is to migrate, including code typed against concrete key classes such as RSAPublicKey. It runs on source alone, with no build or classpath, and ships as a CLI, a Maven plugin on Maven Central and a GitHub Action, with Markdown, JSON and SARIF output. Apache-2.0.

Checklist

  • I searched the list and existing issues for duplicates.
  • I changed README_SOURCE.md, not the generated README.md.
  • This pull request contains one suggestion.
  • The suggestion is relevant to Java or the JVM and fits its chosen category.
  • I used the canonical project or resource link.
  • The suggestion is current and maintained.
  • The concise, neutral description explains its distinguishing value and ends with punctuation.
  • Licensing is clear and any restrictive terms are disclosed where applicable.

Disclosure: I maintain this project.


Summary by cubic

Adds PQC Migration Readiness to the Code Analysis list in README_SOURCE.md.

The tool is a static analyzer that scans Java source for quantum-vulnerable JCA usage (RSA, ECDSA, (EC)DH) and ranks each site by how hard it is to migrate to post-quantum cryptography, running on source alone with no build or classpath required.

Written for commit 4fe6cc3. Summary will update on new commits.

Review in cubic

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Re-trigger cubic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant