All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.
References
https://nvd.nist.gov/vuln/detail/CVE-2019-10249
https://github.com/eclipse/xtext-xte…