Android Signing

The Jenkins project announced an unresolved security vulnerability affecting the current version of this plugin (why?):
List of issues
KeySummaryCreatedUpdated
JENKINS-71330Security vulnerability still shows even after update
JENKINS-71124SignApksBuilder does not work with JDK 17
JENKINS-69278Missing permission check allows listing workspace contents
JENKINS-58310Can I use the android signing plugin to sign android app bundles?