GeoWave is an Eclipse LocationTech project, and vulnerabilities in it are handled under the Eclipse Foundation Security Policy.
Please do not report security vulnerabilities in public GitHub issues or pull requests.
Report them privately to the Eclipse Foundation Security Team instead, either through the confidential vulnerability report tracker or by email to security@eclipse-foundation.org. Include the affected GeoWave version, the component or datastore involved, and steps to reproduce.
Development happens on master, the 3.x line, which requires Java 21. 2.x-jdk8 is the last line
that runs on Java 8.