| Version | Supported |
|---|---|
| 2.0.x | Yes |
Please open a private GitHub security advisory on acefun29/jswarm, or contact the maintainers via the repository.
Do not file public issues for undisclosed vulnerabilities.
- Artifacts are consumed from JitPack.
- GitHub Release may include SBOM and sha256 checksums for Actions-built assets.
- Release Artifact Attestations (if present) do not cover JitPack-built jars. JitPack rebuilds from source on demand; production consumers may pin a commit hash and verify checksums independently.
- This project does not publish GPG-signed artifacts to Maven Central in the current channel.