Hi. your junior colleague might be interested in the security answer here https://jitpack.io/docs/FAQ/. It's an important matter so will be happy to answer any more questions via email/gitter.
You can also run JitPack on-premises and have full control over build artifacts.
You can also run JitPack on-premises and have full control over build artifacts.