These are all security issues fixed in the jsr-305-3.0.2-1.2 package on the GA media of openSUSE Tumbleweed.
{ "binaries": [ { "jsr-305": "3.0.2-1.2", "jsr-305-javadoc": "3.0.2-1.2" } ] }